// For flags

CVE-2013-4130

spice: unsafe clients ring access abort

Severity Score

7.5
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The (1) red_channel_pipes_add_type and (2) red_channel_pipes_add_empty_msg functions in server/red_channel.c in SPICE before 0.12.4 do not properly perform ring loops, which might allow remote attackers to cause a denial of service (reachable assertion and server exit) by triggering a network error.

Las funciones (1) red_channel_pipes_add_type y (2) red_channel_pipes_add_empty_msg ein server/red_channel.c en SPICE before 0.12.4, no realizan bucles en anillo adecuadamente, lo que podría permitir a atacantes remotos realizar una denegación de servicio (aserción alcanzable y salida del servidor) mediante un mensaje de error de red.

The rhev-hypervisor6 package provides a Red Hat Enterprise Virtualization Hypervisor ISO disk image. The Red Hat Enterprise Virtualization Hypervisor is a dedicated Kernel-based Virtual Machine hypervisor. It includes everything necessary to run and manage virtual machines: A subset of the Red Hat Enterprise Linux operating environment and the Red Hat Enterprise Virtualization Agent. Note: Red Hat Enterprise Virtualization Hypervisor is only available for the Intel 64 and AMD64 architectures with virtualization extensions. Upgrade Note: If you upgrade the Red Hat Enterprise Virtualization Hypervisor through the 3.2 Manager administration portal, the Host may appear with the status of "Install Failed". If this happens, place the host into maintenance mode, then activate it again to get the host back to an "Up" state.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
None
Integrity
None
Availability
Partial
Attack Vector
Adjacent
Attack Complexity
High
Authentication
Single
Confidentiality
None
Integrity
None
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2013-06-12 CVE Reserved
  • 2013-08-14 CVE Published
  • 2024-08-06 CVE Updated
  • 2025-03-30 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-399: Resource Management Errors
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Spice Project
Search vendor "Spice Project"
Spice
Search vendor "Spice Project" for product "Spice"
<= 0.12.3
Search vendor "Spice Project" for product "Spice" and version " <= 0.12.3"
-
Affected
Spice Project
Search vendor "Spice Project"
Spice
Search vendor "Spice Project" for product "Spice"
0.5.2
Search vendor "Spice Project" for product "Spice" and version "0.5.2"
-
Affected
Spice Project
Search vendor "Spice Project"
Spice
Search vendor "Spice Project" for product "Spice"
0.5.3
Search vendor "Spice Project" for product "Spice" and version "0.5.3"
-
Affected
Spice Project
Search vendor "Spice Project"
Spice
Search vendor "Spice Project" for product "Spice"
0.6.0
Search vendor "Spice Project" for product "Spice" and version "0.6.0"
-
Affected
Spice Project
Search vendor "Spice Project"
Spice
Search vendor "Spice Project" for product "Spice"
0.6.1
Search vendor "Spice Project" for product "Spice" and version "0.6.1"
-
Affected
Spice Project
Search vendor "Spice Project"
Spice
Search vendor "Spice Project" for product "Spice"
0.6.2
Search vendor "Spice Project" for product "Spice" and version "0.6.2"
-
Affected
Spice Project
Search vendor "Spice Project"
Spice
Search vendor "Spice Project" for product "Spice"
0.6.3
Search vendor "Spice Project" for product "Spice" and version "0.6.3"
-
Affected
Spice Project
Search vendor "Spice Project"
Spice
Search vendor "Spice Project" for product "Spice"
0.6.4
Search vendor "Spice Project" for product "Spice" and version "0.6.4"
-
Affected
Spice Project
Search vendor "Spice Project"
Spice
Search vendor "Spice Project" for product "Spice"
0.7.0
Search vendor "Spice Project" for product "Spice" and version "0.7.0"
-
Affected
Spice Project
Search vendor "Spice Project"
Spice
Search vendor "Spice Project" for product "Spice"
0.7.1
Search vendor "Spice Project" for product "Spice" and version "0.7.1"
-
Affected
Spice Project
Search vendor "Spice Project"
Spice
Search vendor "Spice Project" for product "Spice"
0.7.2
Search vendor "Spice Project" for product "Spice" and version "0.7.2"
-
Affected
Spice Project
Search vendor "Spice Project"
Spice
Search vendor "Spice Project" for product "Spice"
0.7.3
Search vendor "Spice Project" for product "Spice" and version "0.7.3"
-
Affected
Spice Project
Search vendor "Spice Project"
Spice
Search vendor "Spice Project" for product "Spice"
0.8.0
Search vendor "Spice Project" for product "Spice" and version "0.8.0"
-
Affected
Spice Project
Search vendor "Spice Project"
Spice
Search vendor "Spice Project" for product "Spice"
0.8.1
Search vendor "Spice Project" for product "Spice" and version "0.8.1"
-
Affected
Spice Project
Search vendor "Spice Project"
Spice
Search vendor "Spice Project" for product "Spice"
0.8.2
Search vendor "Spice Project" for product "Spice" and version "0.8.2"
-
Affected
Spice Project
Search vendor "Spice Project"
Spice
Search vendor "Spice Project" for product "Spice"
0.8.3
Search vendor "Spice Project" for product "Spice" and version "0.8.3"
-
Affected
Spice Project
Search vendor "Spice Project"
Spice
Search vendor "Spice Project" for product "Spice"
0.9.0
Search vendor "Spice Project" for product "Spice" and version "0.9.0"
-
Affected
Spice Project
Search vendor "Spice Project"
Spice
Search vendor "Spice Project" for product "Spice"
0.9.1
Search vendor "Spice Project" for product "Spice" and version "0.9.1"
-
Affected
Spice Project
Search vendor "Spice Project"
Spice
Search vendor "Spice Project" for product "Spice"
0.10.0
Search vendor "Spice Project" for product "Spice" and version "0.10.0"
-
Affected
Spice Project
Search vendor "Spice Project"
Spice
Search vendor "Spice Project" for product "Spice"
0.10.1
Search vendor "Spice Project" for product "Spice" and version "0.10.1"
-
Affected
Spice Project
Search vendor "Spice Project"
Spice
Search vendor "Spice Project" for product "Spice"
0.11.0
Search vendor "Spice Project" for product "Spice" and version "0.11.0"
-
Affected
Spice Project
Search vendor "Spice Project"
Spice
Search vendor "Spice Project" for product "Spice"
0.11.3
Search vendor "Spice Project" for product "Spice" and version "0.11.3"
-
Affected
Spice Project
Search vendor "Spice Project"
Spice
Search vendor "Spice Project" for product "Spice"
0.12.0
Search vendor "Spice Project" for product "Spice" and version "0.12.0"
-
Affected
Spice Project
Search vendor "Spice Project"
Spice
Search vendor "Spice Project" for product "Spice"
0.12.2
Search vendor "Spice Project" for product "Spice" and version "0.12.2"
-
Affected
Canonical
Search vendor "Canonical"
Ubuntu Linux
Search vendor "Canonical" for product "Ubuntu Linux"
13.04
Search vendor "Canonical" for product "Ubuntu Linux" and version "13.04"
-
Affected