Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2020-0471

Опубликовано: 11 фев. 2020
Источник: oracle-oval
Платформа: Oracle Linux 6

Описание

ELSA-2020-0471: spice-gtk security update (MODERATE)

[0.26-8.2]

  • Fix insufficient encoding checks for LZ Resolves: rhbz#1598651

[0.26-8.1]

  • Fix flexible array buffer overflow Resolves: rhbz#1596008

Обновленные пакеты

Oracle Linux 6

Oracle Linux x86_64

spice-glib

0.26-8.el6_10.2

spice-glib-devel

0.26-8.el6_10.2

spice-gtk

0.26-8.el6_10.2

spice-gtk-devel

0.26-8.el6_10.2

spice-gtk-python

0.26-8.el6_10.2

spice-gtk-tools

0.26-8.el6_10.2

Oracle Linux i686

spice-glib

0.26-8.el6_10.2

spice-glib-devel

0.26-8.el6_10.2

spice-gtk

0.26-8.el6_10.2

spice-gtk-devel

0.26-8.el6_10.2

spice-gtk-python

0.26-8.el6_10.2

spice-gtk-tools

0.26-8.el6_10.2

Связанные CVE

Связанные уязвимости

CVSS3: 7.6
ubuntu
больше 7 лет назад

Multiple integer overflow and buffer overflow issues were discovered in spice-client's handling of LZ compressed frames. A malicious server could cause the client to crash or, potentially, execute arbitrary code.

CVSS3: 7.6
redhat
больше 7 лет назад

Multiple integer overflow and buffer overflow issues were discovered in spice-client's handling of LZ compressed frames. A malicious server could cause the client to crash or, potentially, execute arbitrary code.

CVSS3: 7.6
nvd
больше 7 лет назад

Multiple integer overflow and buffer overflow issues were discovered in spice-client's handling of LZ compressed frames. A malicious server could cause the client to crash or, potentially, execute arbitrary code.

CVSS3: 7.6
debian
больше 7 лет назад

Multiple integer overflow and buffer overflow issues were discovered i ...

CVSS3: 8.8
github
больше 3 лет назад

Multiple integer overflow and buffer overflow issues were discovered in spice-client's handling of LZ compressed frames. A malicious server could cause the client to crash or, potentially, execute arbitrary code.