Heap-based buffer overflow in SPICE before 0.12.6 allows guest OS users to read and write to arbitrary memory locations on the host via guest QXL commands related to surface creation.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-3371-1 | spice security update |
EUVD |
EUVD-2015-5248 | Heap-based buffer overflow in SPICE before 0.12.6 allows guest OS users to read and write to arbitrary memory locations on the host via guest QXL commands related to surface creation. |
Ubuntu USN |
USN-2766-1 | Spice vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-06T06:41:08.985Z
Reserved: 2015-07-01T00:00:00
Link: CVE-2015-5261
No data.
Status : Deferred
Published: 2016-06-07T14:06:07.683
Modified: 2025-04-12T10:46:40.837
Link: CVE-2015-5261
OpenCVE Enrichment
No data.
Debian DSA
EUVD
Ubuntu USN