Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
SPICE could be made to crash if it received specially crafted network
traffic.
Software Description:
- spice: SPICE protocol client and server library
Details:
Tomas Jamrisko discovered that SPICE incorrectly handled long passwords in
SPICE tickets. An attacker could use this issue to cause the SPICE server
to crash, resulting in a denial of service.
The problem can be corrected by updating your system to the following package versions: Ubuntu 13.10: libspice-server1 0.12.4-0nocelt1ubuntu0.1 Ubuntu 13.04: libspice-server1 0.12.2-0nocelt2expubuntu1.2 After a standard system update you need to restart applications using the SPICE protocol, such as QEMU, to make all the necessary changes.
https://ubuntu.com/security/notices/USN-2027-1
CVE-2013-4282
Get the latest Linux and open source security news straight to your inbox.