SCIENTIFIC-LINUX-ERRATA Archives

October 2013

SCIENTIFIC-LINUX-ERRATA@LISTSERV.FNAL.GOV

Options: Use Monospaced Font
Show Text Part by Default
Show All Mail Headers

Message: [<< First] [< Prev] [Next >] [Last >>]
Topic: [<< First] [< Prev] [Next >] [Last >>]
Author: [<< First] [< Prev] [Next >] [Last >>]

Print Reply
Subject:
From:
Pat Riehecky <[log in to unmask]>
Reply To:
Date:
Wed, 30 Oct 2013 14:53:08 +0000
Content-Type:
text/plain
Parts/Attachments:
text/plain (22 lines)
Synopsis:          Important: qspice security update
Advisory ID:       SLSA-2013:1474-1
Issue Date:        2013-10-29
CVE Numbers:       CVE-2013-4282
--

A stack-based buffer overflow flaw was found in the way the
reds_handle_ticket() function in the spice-server library handled
decryption of ticket data provided by the client. A remote user able to
initiate a SPICE connection to an application acting as a SPICE server
could use this flaw to crash the application. (CVE-2013-4282)
--

SL5
  x86_64
    qspice-debuginfo-0.3.0-56.el5_10.1.x86_64.rpm
    qspice-libs-0.3.0-56.el5_10.1.x86_64.rpm
    qspice-0.3.0-56.el5_10.1.x86_64.rpm
    qspice-libs-devel-0.3.0-56.el5_10.1.x86_64.rpm

- Scientific Linux Development Team

ATOM RSS1 RSS2