Oval Definition:oval:com.redhat.rhsa:def:20161205
Revision Date:2016-06-06Version:638
Title:RHSA-2016:1205: spice security update (Important)
Description:The Simple Protocol for Independent Computing Environments (SPICE) is a remote display system built for virtual environments which allows the user to view a computing 'desktop' environment not only on the machine where it is running, but from anywhere on the Internet and from a wide variety of machine architectures.

Security Fix(es):

  • A memory allocation flaw, leading to a heap-based buffer overflow, was found in spice's smartcard interaction, which runs under the QEMU-KVM context on the host. A user connecting to a guest VM using spice could potentially use this flaw to crash the QEMU-KVM process or execute arbitrary code with the privileges of the host's QEMU-KVM process. (CVE-2016-0749)

  • A memory access flaw was found in the way spice handled certain guests using crafted primary surface parameters. A user in a guest could use this flaw to read from and write to arbitrary memory locations on the host. (CVE-2016-2150)

    The CVE-2016-0749 issue was discovered by Jing Zhao (Red Hat) and the CVE-2016-2150 issue was discovered by Frediano Ziglio (Red Hat).
  • Family:unixClass:patch
    Status:Reference(s):CVE-2016-0749
    CVE-2016-2150
    RHSA-2016:1205
    RHSA-2016:1205-00
    RHSA-2016:1205-01
    Platform(s):Red Hat Enterprise Linux 7
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 7 is installed
  • AND
  • spice-server is earlier than 0:0.12.4-15.el7_2.1
  • AND spice-server is signed with Red Hat redhatrelease2 key
  • spice-server-devel is earlier than 0:0.12.4-15.el7_2.1
  • AND spice-server-devel is signed with Red Hat redhatrelease2 key
  • BACK