[Forgot Password]
Login  Register Subscribe

30389

 
 

423868

 
 

247085

 
 

909

 
 

194218

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

RHSA-2016:1205-01 -- Redhat spice

ID: oval:org.secpod.oval:def:501834Date: (C)2016-06-10   (M)2023-12-20
Class: PATCHFamily: unix




The Simple Protocol for Independent Computing Environments is a remote display system built for virtual environments which allows the user to view a computing "desktop" environment not only on the machine where it is running, but from anywhere on the Internet and from a wide variety of machine architectures. Security Fix: * A memory allocation flaw, leading to a heap-based buffer overflow, was found in spice"s smartcard interaction, which runs under the QEMU-KVM context on the host. A user connecting to a guest VM using spice could potentially use this flaw to crash the QEMU-KVM process or execute arbitrary code with the privileges of the host"s QEMU-KVM process. * A memory access flaw was found in the way spice handled certain guests using crafted primary surface parameters. A user in a guest could use this flaw to read from and write to arbitrary memory locations on the host. The CVE-2016-0749 issue was discovered by Jing Zhao and the CVE-2016-2150 issue was discovered by Frediano Ziglio .

Platform:
Red Hat Enterprise Linux 7
Product:
spice
spice-server
Reference:
RHSA-2016:1205-01
CVE-2016-0749
CVE-2016-2150
CVE    2
CVE-2016-0749
CVE-2016-2150
CPE    3
cpe:/o:redhat:enterprise_linux:7
cpe:/a:redhat:spice
cpe:/a:spice_project:spice-server

© SecPod Technologies