Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2016:1259-1

Опубликовано: 07 мая 2016
Источник: suse-cvrf

Описание

Security update for spice

Spice was updated to fix three security issues.

The following vulnerabilities were fixed:

  • CVE-2015-3247: heap corruption in the spice server (bsc#944460)
  • CVE-2015-5261: Guest could have accessed host memory using crafted images (bsc#948976)
  • CVE-2015-5260: Insufficient validation of surface_id parameter could have caused a crash (bsc#944787)

Список пакетов

SUSE Linux Enterprise Server 11 SP4
libspice-server1-0.12.4-5.1
SUSE Linux Enterprise Server for SAP Applications 11 SP4
libspice-server1-0.12.4-5.1
SUSE Linux Enterprise Software Development Kit 11 SP4
libspice-server-devel-0.12.4-5.1

Описание

Race condition in the worker_update_monitors_config function in SPICE 0.12.4 allows a remote authenticated guest user to cause a denial of service (heap-based memory corruption and QEMU-KVM crash) or possibly execute arbitrary code on the host via unspecified vectors.


Затронутые продукты
SUSE Linux Enterprise Server 11 SP4:libspice-server1-0.12.4-5.1
SUSE Linux Enterprise Server for SAP Applications 11 SP4:libspice-server1-0.12.4-5.1
SUSE Linux Enterprise Software Development Kit 11 SP4:libspice-server-devel-0.12.4-5.1

Ссылки

Описание

Heap-based buffer overflow in SPICE before 0.12.6 allows guest OS users to cause a denial of service (heap-based memory corruption and QEMU-KVM crash) or possibly execute arbitrary code on the host via QXL commands related to the surface_id parameter.


Затронутые продукты
SUSE Linux Enterprise Server 11 SP4:libspice-server1-0.12.4-5.1
SUSE Linux Enterprise Server for SAP Applications 11 SP4:libspice-server1-0.12.4-5.1
SUSE Linux Enterprise Software Development Kit 11 SP4:libspice-server-devel-0.12.4-5.1

Ссылки

Описание

Heap-based buffer overflow in SPICE before 0.12.6 allows guest OS users to read and write to arbitrary memory locations on the host via guest QXL commands related to surface creation.


Затронутые продукты
SUSE Linux Enterprise Server 11 SP4:libspice-server1-0.12.4-5.1
SUSE Linux Enterprise Server for SAP Applications 11 SP4:libspice-server1-0.12.4-5.1
SUSE Linux Enterprise Software Development Kit 11 SP4:libspice-server-devel-0.12.4-5.1

Ссылки
Уязвимость SUSE-SU-2016:1259-1