Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Heap-based buffer overflow in SPICE before 0.12.6 allows guest OS users to cause a denial of service (heap-based memory corruption and QEMU-KVM crash) or possibly execute arbitrary code on the host via QXL commands related to the surface_id parameter.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
spice 缓冲区错误漏洞
Vulnerability Description
spice是一个企业虚拟化桌面版所使用的自适应远程呈现开源协议。该产品主要用于将用户与其虚拟桌面进行连接,能够提供与物理桌面完全相同的最终用户体验。 spice 0.12.6之前版本存在缓冲区错误漏洞。攻击者利用该漏洞导致系统拒绝服务(基于堆的内存损坏和QEMU-KVM崩溃),或执行任意代码。
CVSS Information
N/A
Vulnerability Type
N/A