A vulnerability was discovered in SPICE before version 0.14.1 where the generated code used for demarshalling messages lacked sufficient bounds checks. A malicious client or server, after authentication, could send specially crafted messages to its peer which would result in a crash or, potentially, other impacts.
[
{
"signature_type": "Line",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"237635957984403839304665832143033537380",
"59811238309738357804800226278278585342",
"131838818256843794640739880791407204304"
]
},
"deprecated": false,
"source": "https://gitlab.freedesktop.org/spice/spice-common@bb15d4815ab586b4c4a20f4a565970a44824c42c",
"target": {
"file": "tests/test-marshallers.c"
},
"id": "CVE-2018-10873-361f0cc0"
},
{
"signature_type": "Line",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"250808978833896652379186067368034359240"
]
},
"deprecated": false,
"source": "https://gitlab.freedesktop.org/spice/spice-common@bb15d4815ab586b4c4a20f4a565970a44824c42c",
"target": {
"file": "tests/test-marshallers.h"
},
"id": "CVE-2018-10873-62f66cc9"
}
]