6.6

CVE-2010-0429

libspice, as used in QEMU-KVM in the Hypervisor (aka rhev-hypervisor) in Red Hat Enterprise Virtualization (RHEV) 2.2 and qspice 0.3.0, does not properly restrict the addresses upon which memory-management actions are performed, which allows guest OS users to cause a denial of service (guest OS crash) or possibly gain privileges via unspecified vectors.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Redhat ≫ Qspice Version 0.3.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.31% 0.226
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.6 2.7 10
AV:L/AC:M/Au:S/C:C/I:C/A:C
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://rhn.redhat.com/errata/RHSA-2010-0622.html
Patch
Vendor Advisory
https://rhn.redhat.com/errata/RHSA-2010-0633.html
Patch
Vendor Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=568701