CVE-2013-4282: Red Hat Enterprise Linux

Medium severity, CVSS 5.0. EPSS: 2.7% chance of exploitation in the next 30 days.

Stack-based buffer overflow in the reds_handle_ticket function in server/reds.c in SPICE 0.12.0 allows remote attackers to cause a denial of service (crash) via a long password in a SPICE ticket.

Affected products

  • Red Hat Enterprise Linux: version 5 only; version 6.0 only
  • Red Hat Enterprise Virtualization: version 3.0 only
  • Spice Project Spice: version 0.12.0 only

Published 2013-11-02. Last modified 2026-06-16.