Heap-based Buffer Overflow in SPICE Smartcard Interaction

Heap-based Buffer Overflow in SPICE Smartcard Interaction

CVE-2016-0749 · HIGH Severity

AV:N/AC:L/AU:N/C:C/I:C/A:C

The smartcard interaction in SPICE allows remote attackers to cause a denial of service (QEMU-KVM process crash) or possibly execute arbitrary code via vectors related to connecting to a guest VM, which triggers a heap-based buffer overflow.

Learn more about our Web Application Penetration Testing UK.