Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2019:0176-1

Опубликовано: 14 фев. 2019
Источник: suse-cvrf

Описание

Security update for spice

This update for spice fixes the following issues:

Security issue fixed:

  • CVE-2019-3813: Fixed a out-of-bounds read in the memslot_get_virt function that could lead to denial-of-service or code-execution (bsc#1122706).

This update was imported from the SUSE:SLE-12-SP3:Update update project.

Список пакетов

openSUSE Leap 42.3
libspice-server-devel-0.12.8-13.1
libspice-server1-0.12.8-13.1
spice-0.12.8-13.1

Описание

Spice, versions 0.5.2 through 0.14.1, are vulnerable to an out-of-bounds read due to an off-by-one error in memslot_get_virt. This may lead to a denial of service, or, in the worst case, code-execution by unauthenticated attackers.


Затронутые продукты
openSUSE Leap 42.3:libspice-server-devel-0.12.8-13.1
openSUSE Leap 42.3:libspice-server1-0.12.8-13.1
openSUSE Leap 42.3:spice-0.12.8-13.1

Ссылки
Уязвимость openSUSE-SU-2019:0176-1