Описание
Security update for spice
This update for spice fixes the following issues:
Security issue fixed:
- CVE-2019-3813: Fixed a out-of-bounds read in the memslot_get_virt function that could lead to denial-of-service or code-execution (bsc#1122706).
This update was imported from the SUSE:SLE-12-SP3:Update update project.
Список пакетов
openSUSE Leap 42.3
libspice-server-devel-0.12.8-13.1
libspice-server1-0.12.8-13.1
spice-0.12.8-13.1
Ссылки
- E-Mail link for openSUSE-SU-2019:0176-1
- SUSE Security Ratings
Описание
Spice, versions 0.5.2 through 0.14.1, are vulnerable to an out-of-bounds read due to an off-by-one error in memslot_get_virt. This may lead to a denial of service, or, in the worst case, code-execution by unauthenticated attackers.
Затронутые продукты
openSUSE Leap 42.3:libspice-server-devel-0.12.8-13.1
openSUSE Leap 42.3:libspice-server1-0.12.8-13.1
openSUSE Leap 42.3:spice-0.12.8-13.1
Ссылки
- CVE-2019-3813
- SUSE Bug 1122706