Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2018:2598-1

Опубликовано: 04 сент. 2018
Источник: suse-cvrf

Описание

Security update for spice

This update for spice fixes the following issues:

Security issues fixed:

  • CVE-2018-10873: Fix potential heap corruption when demarshalling (bsc#1104448)
  • CVE-2018-10893: Avoid buffer overflow on image lz checks (bsc#1101295)

This update was imported from the SUSE:SLE-15:Update update project.

Список пакетов

openSUSE Leap 15.0
libspice-server-devel-0.14.0-lp150.3.3.1
libspice-server1-0.14.0-lp150.3.3.1
spice-0.14.0-lp150.3.3.1

Описание

A vulnerability was discovered in SPICE before version 0.14.1 where the generated code used for demarshalling messages lacked sufficient bounds checks. A malicious client or server, after authentication, could send specially crafted messages to its peer which would result in a crash or, potentially, other impacts.


Затронутые продукты
openSUSE Leap 15.0:libspice-server-devel-0.14.0-lp150.3.3.1
openSUSE Leap 15.0:libspice-server1-0.14.0-lp150.3.3.1
openSUSE Leap 15.0:spice-0.14.0-lp150.3.3.1

Ссылки

Описание

Multiple integer overflow and buffer overflow issues were discovered in spice-client's handling of LZ compressed frames. A malicious server could cause the client to crash or, potentially, execute arbitrary code.


Затронутые продукты
openSUSE Leap 15.0:libspice-server-devel-0.14.0-lp150.3.3.1
openSUSE Leap 15.0:libspice-server1-0.14.0-lp150.3.3.1
openSUSE Leap 15.0:spice-0.14.0-lp150.3.3.1

Ссылки