Oval Definition:oval:org.cisecurity:def:200
Revision Date:2016-02-08Version:2
Title:DSA-3354-1 -- spice -- security update
Description:Frediano Ziglio of Red Hat discovered a race condition flaw in spice's worker_update_monitors_config() function, leading to a heap-based memory corruption. A malicious user in a guest can take advantage of this flaw to cause a denial of service (QEMU process crash) or, potentially execute arbitrary code on the host with the privileges of the hosting QEMU process.
Family:unixClass:patch
Status:ACCEPTEDReference(s):CVE-2015-3247
DSA-3354-1
Platform(s):Debian 8
Product(s):spice
Definition Synopsis
  • Debian 8 is installed
  • AND spice is earlier than 0:0.12.5-1+deb8u1
  • BACK