{"id":"CVE-2018-10893","details":"Multiple integer overflow and buffer overflow issues were discovered in spice-client's handling of LZ compressed frames. A malicious server could cause the client to crash or, potentially, execute arbitrary code.","modified":"2026-04-16T01:43:56.159271423Z","published":"2018-09-11T15:29:00.233Z","related":["SUSE-SU-2018:2563-1","SUSE-SU-2018:2566-1","SUSE-SU-2018:2584-1","SUSE-SU-2018:2593-1","SUSE-SU-2018:2594-1","SUSE-SU-2018:2595-1","SUSE-SU-2018:2709-1","SUSE-SU-2020:3841-1","SUSE-SU-2020:3842-1","openSUSE-SU-2024:11397-1","openSUSE-SU-2024:11398-1"],"references":[{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2019:2229"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2020:0471"},{"type":"FIX","url":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10893"},{"type":"FIX","url":"https://lists.freedesktop.org/archives/spice-devel/2018-July/044489.html"}],"affected":[{"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2018-10893.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}