CVE-2010-0429

libspice, as used in QEMU-KVM in the Hypervisor (aka rhev-hypervisor) in Red Hat Enterprise Virtualization (RHEV) 2.2 and qspice 0.3.0, does not properly restrict the addresses upon which memory-management actions are performed, which allows guest OS users to cause a denial of service (guest OS crash) or possibly gain privileges via unspecified vectors.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.6 UNKNOWN
LOCAL
MEDIUM
AV:L/AC:M/Au:S/C:C/I:C/A:C
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 15%
VendorProductVersion
redhatenterprise_virtualization
2.2
redhatqspice
0.3.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
spice
bullseye
0.14.3-2.1
fixed
bookworm
0.15.1-1
fixed
sid
0.15.2-1
fixed
trixie
0.15.2-1
fixed
Common Weakness Enumeration