Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2019:0229-1

Опубликовано: 05 фев. 2019
Источник: suse-cvrf

Описание

Security update for spice

This update for spice fixes the following issues:

Security issue fixed:

  • CVE-2019-3813: Fixed a out-of-bounds read in the memslot_get_virt function that could lead to denial-of-service or code-execution (bsc#1122706).

Список пакетов

SUSE Linux Enterprise Server 12-LTSS
libspice-server1-0.12.4-8.21.1

Описание

Spice, versions 0.5.2 through 0.14.1, are vulnerable to an out-of-bounds read due to an off-by-one error in memslot_get_virt. This may lead to a denial of service, or, in the worst case, code-execution by unauthenticated attackers.


Затронутые продукты
SUSE Linux Enterprise Server 12-LTSS:libspice-server1-0.12.4-8.21.1

Ссылки