Home
Reading
Searching
Subscribe
Sponsors
Statistics
Posting
Contact
Spam
Lists
Links
About
Hosting
Filtering
Features Download
Marketing
Archives
FAQ
Blog
 
Gmane
From: Pat Riehecky <riehecky-13hema8v3vg <at> public.gmane.org>
Subject: Security ERRATA Important: spice-server on SL6.x x86_64
Newsgroups: gmane.linux.scientific.errata
Date: Wednesday 30th October 2013 14:52:54 UTC (over 3 years ago)
Synopsis:          Important: spice-server security update
Advisory ID:       SLSA-2013:1473-1
Issue Date:        2013-10-29
CVE Numbers:       CVE-2013-4282
--

A stack-based buffer overflow flaw was found in the way the
reds_handle_ticket() function in the spice-server library handled
decryption of ticket data provided by the client. A remote user able to
initiate a SPICE connection to an application acting as a SPICE server
could use this flaw to crash the application. (CVE-2013-4282)
--

SL6
  x86_64
    spice-server-0.12.0-12.el6_4.5.x86_64.rpm
    spice-server-debuginfo-0.12.0-12.el6_4.5.x86_64.rpm
    spice-server-devel-0.12.0-12.el6_4.5.x86_64.rpm

- Scientific Linux Development Team
 
CD: 44ms