SB2018072712 - Multiple vulnerabilities in SPICE SPICE
Published: July 27, 2018 Updated: July 17, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 2 vulnerabilities.
1) Input validation error (CVE-ID: CVE-2016-9578)
The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.
A vulnerability was discovered in SPICE before 0.13.90 in the server's protocol handling. An attacker able to connect to the SPICE server could send crafted messages which would cause the process to crash.
2) Buffer overflow (CVE-ID: CVE-2016-9577)
The vulnerability allows a remote authenticated user to execute arbitrary code.
A vulnerability was discovered in SPICE before 0.13.90 in the server's protocol handling. An authenticated attacker could send crafted messages to the SPICE server causing a heap overflow leading to a crash or possible code execution.
Remediation
Install update from vendor's website.
References
- http://rhn.redhat.com/errata/RHSA-2017-0253.html
- http://rhn.redhat.com/errata/RHSA-2017-0549.html
- http://www.securityfocus.com/bid/96118
- https://access.redhat.com/errata/RHSA-2017:0254
- https://access.redhat.com/errata/RHSA-2017:0552
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-9578
- https://www.debian.org/security/2017/dsa-3790
- http://www.securityfocus.com/bid/96040
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-9577