qspice: denial of service
Package(s): | qspice | CVE #(s): | CVE-2013-4282 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Created: | October 30, 2013 | Updated: | May 18, 2015 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Description: | From the Red Hat advisory:
A stack-based buffer overflow flaw was found in the way the reds_handle_ticket() function in the spice-server library handled decryption of ticket data provided by the client. A remote user able to initiate a SPICE connection to an application acting as a SPICE server could use this flaw to crash the application. | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Alerts: |
|