Alerts This Week
Warning Icon 1 562
Alerts This Week
Warning Icon 1 562

Debian: DSA-2839-1 Important: Spice Remote Denial of Service Vulnerability

debian
Calendar Grey January 8, 2014
Debian Logo
Numerous security weaknesses detected within the spice library, posing potential remote exploitation threats to Debian users.
Multiple vulnerabilities have been found in spice, a SPICE protocol client and server library

Summary

CVE-2013-4130

David Gibson of Red Hat discovered that SPICE incorrectly handled
certain network errors. A remote user able to initiate a SPICE
connection to an application acting as a SPICE server could use this
flaw to crash the application.

CVE-2013-4282

Tomas Jamrisko of Red Hat discovered that SPICE incorrectly handled
long passwords in SPICE tickets. A remote user able to initiate a
SPICE connection to an application acting as a SPICE server could use
this flaw to crash the application.

Applications acting as a SPICE server must be restarted for this update
to take effect.

For the stable distribution (wheezy), these problems have been fixed in
version 0.11.0-1+deb7u1.

For the testing distribution (jessie), these problems have been fixed in
version 0.12.4-0nocelt2.

For the unstable distribution (sid), these problems have been fixed in
version 0.12.4-0nocelt2.

We recommend that you upgrade your spice packages.

Further information about Debian Security Advisories, how to apply
these u...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Package: spice
CVE ID: CVE-2013-4130 CVE-2013-4282

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here