yocto ▾
›
scarthgap ▾
›
vulnerability
›
CVE-2018-10893
Component Overview
Vulnerability Overview
Name
CVE-2018-10893
Source
NVD (
link
)
Debian (
link
)
Description
Multiple integer overflow and buffer overflow issues were discovered in spice-client's handling of LZ compressed frames. A malicious server could cause the client to crash or, potentially, execute arbitrary code.
CWEs
CWE-122
CWE-190
Published Date
Sep 11, 2018
Updated Date
Jun 17, 2026
Workaround
-
Advisories
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10893
Issue Tracking
https://lists.freedesktop.org/archives/spice-devel/2018-July/044489.html
Mailing List
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10893
Issue Tracking
https://lists.freedesktop.org/archives/spice-devel/2018-July/044489.html
Mailing List
Analysis
#
Affected Component
Analysis
spice
Not Affected
Vulnerability Ratings
#
7.6
other
8.8
other
6.5
CVSSv2
Others affected components
#
Name
Project
Project Version
Version
Status
spice
buildroot
2025.02.x
0.15.2
Not Affected
spice
buildroot
master
0.15.2
Not Affected
spice
openwrt
master
0.15.0-r3
Not Affected
spice
openwrt
openwrt-25.12
0.15.0-r3
Not Affected
spice
yocto
kirkstone
0.14.2+gitX
Not Affected
spice
yocto
master
0.16.0
Not Affected