Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 542
Alerts This Week
Warning Icon 1 542

Ubuntu 13.04 USN-1926-1 Critical SPICE Denial Of Service Issue

ubuntu
Calendar Grey August 14, 2013
Scroller Ubuntu
A potential SPICE security flaw may result in a system crash due to specially designed packets. It's essential to upgrade your Ubuntu installation to address this serious vulnerability.
SPICE could be made to crash if it received specially crafted network traffic.

Summary

SPICE could be made to crash if it received specially crafted network

traffic.

Software Description:

- spice: SPICE protocol client and server library

Details:

David Gibson discovered that SPICE incorrectly handled certain network

errors. An attacker could use this issue to cause the SPICE server to

crash, resulting in a denial of service.

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 13.04:
  libspice-server1                0.12.2-0nocelt2expubuntu1.1

After a standard system update you need to restart applications using the
SPICE protocol, such as QEMU, to make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-1926-1

CVE-2013-4130

Severity
critical
Lowest
Low
Medium
High
Critical

August 14, 2013

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.