A vulnerability was discovered in SPICE before 0.13.90 in the server's protocol handling. An attacker able to connect to the SPICE server could send crafted messages which would cause the process to crash.
https://www.debian.org/security/2017/dsa-3790
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-9578
https://access.redhat.com/errata/RHSA-2017:0552
https://access.redhat.com/errata/RHSA-2017:0254
http://www.securityfocus.com/bid/96118