Oval Definition:oval:com.redhat.rhsa:def:20172471
Revision Date:2017-08-15Version:637
Title:RHSA-2017:2471: spice security update (Important)
Description:The Simple Protocol for Independent Computing Environments (SPICE) is a remote display system built for virtual environments which allows the user to view a computing 'desktop' environment not only on the machine where it is running, but from anywhere on the Internet and from a wide variety of machine architectures.

Security Fix(es):

  • A vulnerability was discovered in spice server's protocol handling. An authenticated attacker could send specially crafted messages to the spice server, causing out-of-bounds memory accesses, leading to parts of server memory being leaked or a crash. (CVE-2017-7506)

    This issue was discovered by Frediano Ziglio (Red Hat).
  • Family:unixClass:patch
    Status:Reference(s):CVE-2017-7506
    RHSA-2017:2471
    RHSA-2017:2471-00
    RHSA-2017:2471-01
    Platform(s):Red Hat Enterprise Linux 7
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 7 is installed
  • AND
  • spice-server is earlier than 0:0.12.8-2.el7.1
  • AND spice-server is signed with Red Hat redhatrelease2 key
  • spice-server-devel is earlier than 0:0.12.8-2.el7.1
  • AND spice-server-devel is signed with Red Hat redhatrelease2 key
  • BACK