Out-of-Bounds Read Vulnerability in Spice by Red Hat
CVE-2019-3813
7.5HIGH
What is CVE-2019-3813?
The Spice software, used for providing remote access to virtual machines, is affected by an out-of-bounds read condition, stemming from an off-by-one error in the function memslot_get_virt. This flaw can permit unauthorized attackers to conduct denial of service attacks or potentially execute arbitrary code, posing significant risks to confidentiality, integrity, and availability of the affected systems.
Affected Version(s)
Spice versions 0.5.2 through 0.14.1