Synopsis: Important: spice security update Advisory ID: SLSA-2015:1890-1 Issue Date: 2015-10-12 CVE Numbers: CVE-2015-5260 CVE-2015-5261 -- A heap-based buffer overflow flaw was found in the way SPICE handled certain guest QXL commands related to surface creation. A user in a guest could use this flaw to read and write arbitrary memory locations on the host. (CVE-2015-5261) A heap-based buffer overflow flaw was found in the way spice handled certain QXL commands related to the "surface_id" parameter. A user in a guest could use this flaw to crash the host QEMU-KVM process or, possibly, execute arbitrary code with the privileges of the host QEMU-KVM process. (CVE-2015-5260) -- SL7 x86_64 spice-debuginfo-0.12.4-9.el7_1.3.x86_64.rpm spice-server-0.12.4-9.el7_1.3.x86_64.rpm spice-server-devel-0.12.4-9.el7_1.3.x86_64.rpm - Scientific Linux Development Team