---
cve: "CVE-2016-9578"
severity: "HIGH"
cvss: 7.5
epss: "2.5%"
vendor: "Red Hat"
kev: false
exploited: false
published: "2018-07-27 21:29:00"
tags: [cve, security, high]
source: tsecurity.de CVE-Dossier
exported: "2026-09-17T13:48:00+02:00"
---

# CVE-2016-9578

> 7.5 HIGH

## Beschreibung

A vulnerability was discovered in SPICE before 0.13.90 in the server's protocol handling. An attacker able to connect to the SPICE server could send crafted messages which would cause the process to crash.

## CVSS-Vektor

```
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Keine | bad |
| UI Interaktion | Keine | bad |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Keine | good |
| I Integrität | Keine | good |
| A Verfügbarkeit | Hoch | bad |

## Patch verfügbar (OSV)

- 34dff543bef7a5201f41c72353a65840bd37c275 (Commit)

## Referenzen

- <https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-9578>
- <https://access.redhat.com/errata/RHSA-2017:0552>
- <https://access.redhat.com/errata/RHSA-2017:0254>
- <http://www.securityfocus.com/bid/96118>
- <https://www.debian.org/security/2017/dsa-3790>
- <http://rhn.redhat.com/errata/RHSA-2017-0253.html>
- <http://rhn.redhat.com/errata/RHSA-2017-0549.html>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2016-9578) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
