Home
Reading
Searching
Subscribe
Sponsors
Statistics
Posting
Contact
Spam
Lists
Links
About
Hosting
Filtering
Features Download
Marketing
Archives
FAQ
Blog
 
Gmane
From: Pat Riehecky <riehecky-13hema8v3vg <at> public.gmane.org>
Subject: Security ERRATA Important: qspice on SL5.x x86_64
Newsgroups: gmane.linux.scientific.errata
Date: Wednesday 30th October 2013 14:53:08 UTC (over 2 years ago)
Synopsis:          Important: qspice security update
Advisory ID:       SLSA-2013:1474-1
Issue Date:        2013-10-29
CVE Numbers:       CVE-2013-4282
--

A stack-based buffer overflow flaw was found in the way the
reds_handle_ticket() function in the spice-server library handled
decryption of ticket data provided by the client. A remote user able to
initiate a SPICE connection to an application acting as a SPICE server
could use this flaw to crash the application. (CVE-2013-4282)
--

SL5
  x86_64
    qspice-debuginfo-0.3.0-56.el5_10.1.x86_64.rpm
    qspice-libs-0.3.0-56.el5_10.1.x86_64.rpm
    qspice-0.3.0-56.el5_10.1.x86_64.rpm
    qspice-libs-devel-0.3.0-56.el5_10.1.x86_64.rpm

- Scientific Linux Development Team
 
CD: 18ms