Alerts This Week
Warning Icon 1 664
Alerts This Week
Warning Icon 1 664

SUSE: 2017:0396-1 Important: Spice DoS and Buffer Overflow Fix

suse
Calendar Grey February 6, 2017
Dist Suse Esm H88
Critical security update released for spice components in SUSE Linux Enterprise. Implement the patch promptly to safeguard your systems.
An update that fixes two vulnerabilities is now available

Summary

This security update for spice fixes the following issues: CVE-2016-9577: A buffer overflow in the spice server could have potentially been used by unauthenticated attackers to execute arbitrary code. (bsc#1023078) CVE-2016-9578: Unauthenticated attackers could have caused a denial of service via a crafted message. (bsc#1023079) Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 11-SP4: zypper in -t patch sdksp4-spice-12970=1 - SUSE Linux Enterprise Server 11-SP4: zypper in -t patch slessp4-spice-12970=1 - SUSE Linux Enterprise Debuginfo 11-SP4: zypper in -t patch dbgsp4-spice-12970=1 To bring your system up-to-date, use "zypper patch". Package List:

References

#1023078 #1023079

Cross- CVE-2016-9577 CVE-2016-9578

Affected Products:

SUSE Linux Enterprise Software Development Kit 11-SP4

SUSE Linux Enterprise Server 11-SP4

SUSE Linux Enterprise Debuginfo 11-SP4

https://www.suse.com/security/cve/CVE-2016-9577.html

https://www.suse.com/security/cve/CVE-2016-9578.html

https://bugzilla.suse.com/1023078

https://bugzilla.suse.com/1023079

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2017:0396-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here