Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 464
Alerts This Week
Warning Icon 1 464

Scientific Linux: SLSA-2017:0253-1 Moderate: Spice-Server Heap Overflow

Scientific Large Esm H446
Moderate: spice-server security update
Date: Mon, 6 Feb 2017 16:40:19 -0000
Reply-To: scientific-linux-users@
Sender: Security Errata for Scientific Linux
 
From: Pat Riehecky 
Subject: Security ERRATA Moderate: spice-server on SL6.x x86_64
MIME-Version: 1.0
Message-ID: <20170206164019.29698.60948@slpackages.fnal.gov>

Synopsis: Moderate: spice-server security update
Advisory ID: SLSA-2017:0253-1
Issue Date: 2017-02-05
CVE Numbers: CVE-2016-9578
 CVE-2016-9577
--

Security Fix(es):

* A vulnerability was discovered in spice in the server's protocol
handling. An authenticated attacker could send crafted messages to the
spice server causing a heap overflow leading to a crash or possible code
execution. (CVE-2016-9577)

* A vulnerability was discovered in spice in the server's protocol
handling. An attacker able to connect to the spice server could send
crafted messages which would cause the process to crash. (CVE-2016-9578)
--

SL6
 x86_64
 spice-server-0.12.4-13.el6_8.2.x86_64.rpm
 spice-server-debuginfo-0.12.4-13.el6_8.2.x86_64.rpm
 spice-server-devel-0.12.4-13.el6_8.2.x86_64.rpm

- Scientific Linux Development Team