Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2020:3841-1

Опубликовано: 16 дек. 2020
Источник: suse-cvrf

Описание

Security update for spice-gtk

This update for spice-gtk fixes the following issues:

  • CVE-2018-10873: Fixed a potential heap corruption when demarshalling (bsc#1104448)
  • CVE-2018-10893: Fixed a buffer overflow on image lz checks (bsc#1101295)

Список пакетов

SUSE Linux Enterprise Server 12 SP2-BCL
libspice-client-glib-2_0-8-0.31-9.10.1
libspice-client-glib-helper-0.31-9.10.1
libspice-client-gtk-2_0-4-0.31-9.10.1
libspice-client-gtk-3_0-4-0.31-9.10.1
libspice-controller0-0.31-9.10.1
typelib-1_0-SpiceClientGlib-2_0-0.31-9.10.1
typelib-1_0-SpiceClientGtk-3_0-0.31-9.10.1
SUSE Linux Enterprise Server 12 SP2-LTSS
libspice-client-glib-2_0-8-0.31-9.10.1
libspice-client-glib-helper-0.31-9.10.1
libspice-client-gtk-2_0-4-0.31-9.10.1
libspice-client-gtk-3_0-4-0.31-9.10.1
libspice-controller0-0.31-9.10.1
typelib-1_0-SpiceClientGlib-2_0-0.31-9.10.1
typelib-1_0-SpiceClientGtk-3_0-0.31-9.10.1
SUSE Linux Enterprise Server for SAP Applications 12 SP2
libspice-client-glib-2_0-8-0.31-9.10.1
libspice-client-glib-helper-0.31-9.10.1
libspice-client-gtk-2_0-4-0.31-9.10.1
libspice-client-gtk-3_0-4-0.31-9.10.1
libspice-controller0-0.31-9.10.1
typelib-1_0-SpiceClientGlib-2_0-0.31-9.10.1
typelib-1_0-SpiceClientGtk-3_0-0.31-9.10.1
SUSE OpenStack Cloud 7
libspice-client-glib-2_0-8-0.31-9.10.1
libspice-client-glib-helper-0.31-9.10.1
libspice-client-gtk-2_0-4-0.31-9.10.1
libspice-client-gtk-3_0-4-0.31-9.10.1
libspice-controller0-0.31-9.10.1
typelib-1_0-SpiceClientGlib-2_0-0.31-9.10.1
typelib-1_0-SpiceClientGtk-3_0-0.31-9.10.1

Описание

A vulnerability was discovered in SPICE before version 0.14.1 where the generated code used for demarshalling messages lacked sufficient bounds checks. A malicious client or server, after authentication, could send specially crafted messages to its peer which would result in a crash or, potentially, other impacts.


Затронутые продукты
SUSE Linux Enterprise Server 12 SP2-BCL:libspice-client-glib-2_0-8-0.31-9.10.1
SUSE Linux Enterprise Server 12 SP2-BCL:libspice-client-glib-helper-0.31-9.10.1
SUSE Linux Enterprise Server 12 SP2-BCL:libspice-client-gtk-2_0-4-0.31-9.10.1
SUSE Linux Enterprise Server 12 SP2-BCL:libspice-client-gtk-3_0-4-0.31-9.10.1

Ссылки

Описание

Multiple integer overflow and buffer overflow issues were discovered in spice-client's handling of LZ compressed frames. A malicious server could cause the client to crash or, potentially, execute arbitrary code.


Затронутые продукты
SUSE Linux Enterprise Server 12 SP2-BCL:libspice-client-glib-2_0-8-0.31-9.10.1
SUSE Linux Enterprise Server 12 SP2-BCL:libspice-client-glib-helper-0.31-9.10.1
SUSE Linux Enterprise Server 12 SP2-BCL:libspice-client-gtk-2_0-4-0.31-9.10.1
SUSE Linux Enterprise Server 12 SP2-BCL:libspice-client-gtk-3_0-4-0.31-9.10.1

Ссылки