Lucene search

K
ubuntuUbuntuUSN-2027-1
HistoryNov 12, 2013 - 12:00 a.m.

SPICE vulnerability

2013-11-1200:00:00
ubuntu.com
44

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

AI Score

6.2

Confidence

Low

EPSS

0.084

Percentile

94.5%

Releases

  • Ubuntu 13.10
  • Ubuntu 13.04

Packages

  • spice - SPICE protocol client and server library

Details

Tomas Jamrisko discovered that SPICE incorrectly handled long passwords in
SPICE tickets. An attacker could use this issue to cause the SPICE server
to crash, resulting in a denial of service.

OSVersionArchitecturePackageVersionFilename
Ubuntu13.10noarchlibspice-server1<Β 0.12.4-0nocelt1ubuntu0.1UNKNOWN
Ubuntu13.10noarchlibspice-server-dev<Β 0.12.4-0nocelt1ubuntu0.1UNKNOWN
Ubuntu13.10noarchspice-client<Β 0.12.4-0nocelt1ubuntu0.1UNKNOWN
Ubuntu13.04noarchlibspice-server1<Β 0.12.2-0nocelt2expubuntu1.2UNKNOWN
Ubuntu13.04noarchlibspice-server-dev<Β 0.12.2-0nocelt2expubuntu1.2UNKNOWN
Ubuntu13.04noarchspice-client<Β 0.12.2-0nocelt2expubuntu1.2UNKNOWN

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

AI Score

6.2

Confidence

Low

EPSS

0.084

Percentile

94.5%