Описание
Security update for spice-gtk
This update for spice-gtk fixes the following issues:
Security issues fixed:
- CVE-2018-10873: Fix potential heap corruption when demarshalling (bsc#1104448)
- CVE-2018-10893: Avoid buffer overflow on image lz checks (bsc#1101295)
Other bugs fixed:
- Add setuid bit to spice-client-glib-usb-acl-helper (bsc#1101420)
Список пакетов
SUSE Linux Enterprise Module for Basesystem 15
libspice-client-glib-2_0-8-0.34-3.3.1
libspice-client-glib-helper-0.34-3.3.1
libspice-client-gtk-3_0-5-0.34-3.3.1
libspice-controller0-0.34-3.3.1
SUSE Linux Enterprise Module for Server Applications 15
spice-gtk-devel-0.34-3.3.1
typelib-1_0-SpiceClientGlib-2_0-0.34-3.3.1
typelib-1_0-SpiceClientGtk-3_0-0.34-3.3.1
Ссылки
- Link for SUSE-SU-2018:2709-1
- E-Mail link for SUSE-SU-2018:2709-1
- SUSE Security Ratings
- SUSE Bug 1101295
- SUSE Bug 1101420
- SUSE Bug 1104448
- SUSE CVE CVE-2018-10873 page
- SUSE CVE CVE-2018-10893 page
Описание
A vulnerability was discovered in SPICE before version 0.14.1 where the generated code used for demarshalling messages lacked sufficient bounds checks. A malicious client or server, after authentication, could send specially crafted messages to its peer which would result in a crash or, potentially, other impacts.
Затронутые продукты
SUSE Linux Enterprise Module for Basesystem 15:libspice-client-glib-2_0-8-0.34-3.3.1
SUSE Linux Enterprise Module for Basesystem 15:libspice-client-glib-helper-0.34-3.3.1
SUSE Linux Enterprise Module for Basesystem 15:libspice-client-gtk-3_0-5-0.34-3.3.1
SUSE Linux Enterprise Module for Basesystem 15:libspice-controller0-0.34-3.3.1
Ссылки
- CVE-2018-10873
- SUSE Bug 1104448
Описание
Multiple integer overflow and buffer overflow issues were discovered in spice-client's handling of LZ compressed frames. A malicious server could cause the client to crash or, potentially, execute arbitrary code.
Затронутые продукты
SUSE Linux Enterprise Module for Basesystem 15:libspice-client-glib-2_0-8-0.34-3.3.1
SUSE Linux Enterprise Module for Basesystem 15:libspice-client-glib-helper-0.34-3.3.1
SUSE Linux Enterprise Module for Basesystem 15:libspice-client-gtk-3_0-5-0.34-3.3.1
SUSE Linux Enterprise Module for Basesystem 15:libspice-controller0-0.34-3.3.1
Ссылки
- CVE-2018-10893
- SUSE Bug 1101295