SCIENTIFIC-LINUX-ERRATA Archives

October 2013

SCIENTIFIC-LINUX-ERRATA@LISTSERV.FNAL.GOV

Options: Use Monospaced Font
Show Text Part by Default
Show All Mail Headers

Message: [<< First] [< Prev] [Next >] [Last >>]
Topic: [<< First] [< Prev] [Next >] [Last >>]
Author: [<< First] [< Prev] [Next >] [Last >>]

Print Reply
Subject:
From:
Pat Riehecky <[log in to unmask]>
Reply To:
Date:
Wed, 30 Oct 2013 14:52:54 +0000
Content-Type:
text/plain
Parts/Attachments:
text/plain (21 lines)
Synopsis:          Important: spice-server security update
Advisory ID:       SLSA-2013:1473-1
Issue Date:        2013-10-29
CVE Numbers:       CVE-2013-4282
--

A stack-based buffer overflow flaw was found in the way the
reds_handle_ticket() function in the spice-server library handled
decryption of ticket data provided by the client. A remote user able to
initiate a SPICE connection to an application acting as a SPICE server
could use this flaw to crash the application. (CVE-2013-4282)
--

SL6
  x86_64
    spice-server-0.12.0-12.el6_4.5.x86_64.rpm
    spice-server-debuginfo-0.12.0-12.el6_4.5.x86_64.rpm
    spice-server-devel-0.12.0-12.el6_4.5.x86_64.rpm

- Scientific Linux Development Team

ATOM RSS1 RSS2