-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-4319-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso October 15, 2018 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : spice CVE ID : CVE-2018-10873 Debian Bug : 906315 Frediano Ziglio reported a missing check in the script to generate demarshalling code in the SPICE protocol client and server library. The generated demarshalling code is prone to multiple buffer overflows. An authenticated attacker can take advantage of this flaw to cause a denial of service (spice server crash), or possibly, execute arbitrary code. For the stable distribution (stretch), this problem has been fixed in version 0.12.8-2.1+deb9u2. We recommend that you upgrade your spice packages. For the detailed security status of spice please refer to its security tracker page at: https://security-tracker.debian.org/tracker/spice Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: debian-security-announce@lists.debian.org -----BEGIN PGP SIGNATURE----- iQKTBAEBCgB9FiEERkRAmAjBceBVMd3uBUy48xNDz0QFAlvE4zNfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2 NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQACgkQBUy48xND z0S16Q/+OocXqtJcbs0jfEjeZEmZ7EhiYbKQfr9erhVviTnRB3wB6dsW5GZY3oAV /Ox9A9fKGyvzR9FaIzKdRZgn2qU56AQBWLs0NU4SPznlCFFv+lUTYTWIWdnyMdDH whA4/VTGAwjbo95Bum7QCa7v+wmBQbMMUGvScZDhZQhf5j9Zfy3KR7xamqVF+Imk CWHQyb//T0T/hOzM7Svvx76grLnQeutNNJrPdMcpO4ZGIKaegUKtDYnR2JaH3F6d 0L77d93d+L6GJJ0BOAufkfL3viV/wPMJgf9NbS0gDjYEyBnF0VfMpbtqaSKwAQ1u sQXpy/COSp8/gkSRMgDOHYoeQlF2nNkDWfjnubAy5LI88p8VDkl2+FqEs6R4srIg cekBnTpqzrlVdirvd33tMf8eDjvQ/kowcu5wgTj/5M9WViZylGcgXQtDpaj9EsOU BTok9p7ilNLZNPbKbMcQ53ebGqxf0lvwgbDzmtqpp0e4Mxo3OEsEMfguvZ4IMP6f i7FVqwG7qENDFXf3Bt3uKjLaErBHSr9hV8kNEKcsTsOBFb+l37LeNvq11HmCVDfm Zr1ayjEJUxBsPW19V9gkDOStbNWqu7XFV5kJTJ2M8Ig0h+/PzwTSDasavrE2qS+1 mFvD4b5Hlmcs0QONMCMGFh1oJ8PYV7WjL7Teij4Ypy8G72WoXHI= =Z9jq -----END PGP SIGNATURE-----