Advisories ยป MGASA-2017-0239

Updated spice packages fix security vulnerability

Publication date: 03 Aug 2017
Modification date: 03 Aug 2017
Type: security
Affected Mageia releases : 5 , 6
CVE: CVE-2017-7506

Description

A vulnerability was discovered in spice, in the server's protocol handling. An
authenticated attacker could send specially crafted messages to the spice
server, causing out-of-bounds memory accesses leading to parts of server memory
being leaked or a crash (CVE-2017-7506).

The Mageia 5 package has been patched to fix this issue.  The Mageia 6 package
has been updated to version 0.13.90, containing fixes for this and several other
issues.
                

References

SRPMS

5/core

6/core