Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2017-2471

Опубликовано: 15 авг. 2017
Источник: oracle-oval
Платформа: Oracle Linux 7

Описание

ELSA-2017-2471: spice security update (IMPORTANT)

[0.12.8-2.1]

  • Redo build properly versioned as a zstream build Related: CVE-2017-7506

[0.12.8-3]

  • Prevent potential buffer/integer overflows with invalid MonitorsConfig messages sent from an authenticated client Resolves: CVE-2017-7506

Обновленные пакеты

Oracle Linux 7

Oracle Linux x86_64

spice-server

0.12.8-2.el7.1

spice-server-devel

0.12.8-2.el7.1

Связанные CVE

Связанные уязвимости

CVSS3: 8.8
ubuntu
больше 8 лет назад

spice versions though 0.13 are vulnerable to out-of-bounds memory access when processing specially crafted messages from authenticated attacker to the spice server resulting into crash and/or server memory leak.

CVSS3: 9.1
redhat
больше 8 лет назад

spice versions though 0.13 are vulnerable to out-of-bounds memory access when processing specially crafted messages from authenticated attacker to the spice server resulting into crash and/or server memory leak.

CVSS3: 8.8
nvd
больше 8 лет назад

spice versions though 0.13 are vulnerable to out-of-bounds memory access when processing specially crafted messages from authenticated attacker to the spice server resulting into crash and/or server memory leak.

CVSS3: 8.8
debian
больше 8 лет назад

spice versions though 0.13 are vulnerable to out-of-bounds memory acce ...

suse-cvrf
больше 8 лет назад

Security update for spice