Описание
Security update for spice
This update for spice fixes the following issues:
Security issue fixed:
- CVE-2019-3813: Fixed a out-of-bounds read in the memslot_get_virt function that could lead to denial-of-service or code-execution (bsc#1122706).
Non-security issue fixed:
- Include spice-server tweak to compensate for performance issues with Windows guests (bsc#1109044).
This update was imported from the SUSE:SLE-15:Update update project.
Список пакетов
openSUSE Leap 15.0
libspice-server-devel-0.14.0-lp150.3.6.1
libspice-server1-0.14.0-lp150.3.6.1
Ссылки
- E-Mail link for openSUSE-SU-2019:0167-1
- SUSE Security Ratings
- SUSE Bug 1109044
- SUSE Bug 1122706
- SUSE CVE CVE-2019-3813 page
Описание
Spice, versions 0.5.2 through 0.14.1, are vulnerable to an out-of-bounds read due to an off-by-one error in memslot_get_virt. This may lead to a denial of service, or, in the worst case, code-execution by unauthenticated attackers.
Затронутые продукты
openSUSE Leap 15.0:libspice-server-devel-0.14.0-lp150.3.6.1
openSUSE Leap 15.0:libspice-server1-0.14.0-lp150.3.6.1
Ссылки
- CVE-2019-3813
- SUSE Bug 1122706