CVE-2017-12194

A flaw was found in the way spice-client processed certain messages sent from the server. An attacker, having control of malicious spice-server, could use this flaw to crash the client or execute arbitrary code with permissions of the user running the client. spice-gtk versions through 0.34 are believed to be vulnerable.

Date published : 2018-03-14

http://www.securityfocus.com/bid/103413

https://bugzilla.redhat.com/show_bug.cgi?id=1501200