Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Date: Mon, 6 Feb 2017 16:21:06 -0000 Reply-To: scientific-linux-users@ Sender: Security Errata for Scientific LinuxFrom: Pat Riehecky Subject: Security ERRATA Moderate: spice on SL7.x x86_64 MIME-Version: 1.0 Message-ID: <20170206162106.29694.14908@slpackages.fnal.gov> Synopsis: Moderate: spice security update Advisory ID: SLSA-2017:0254-1 Issue Date: 2017-02-05 CVE Numbers: CVE-2016-9578 CVE-2016-9577 -- Security Fix(es): * A vulnerability was discovered in spice in the server's protocol handling. An authenticated attacker could send crafted messages to the spice server causing a heap overflow leading to a crash or possible code execution. (CVE-2016-9577) * A vulnerability was discovered in spice in the server's protocol handling. An attacker able to connect to the spice server could send crafted messages which would cause the process to crash. (CVE-2016-9578) -- SL7 x86_64 spice-debuginfo-0.12.4-20.el7_3.x86_64.rpm spice-server-0.12.4-20.el7_3.x86_64.rpm spice-server-devel-0.12.4-20.el7_3.x86_64.rpm - Scientific Linux Development Team