Mageia alert MGASA-2015-0373 (spice)
From: | Mageia Updates <buildsystem-daemon@mageia.org> | |
To: | updates-announce@ml.mageia.org | |
Subject: | [updates-announce] MGASA-2015-0373: Updated spice packages fix CVE-2015-3247 | |
Date: | Tue, 15 Sep 2015 16:55:43 +0200 | |
Message-ID: | <20150915145543.7E0D75A01A@valstar.mageia.org> |
MGASA-2015-0373 - Updated spice packages fix CVE-2015-3247 Publication date: 15 Sep 2015 URL: http://advisories.mageia.org/MGASA-2015-0373.html Type: security Affected Mageia releases: 4, 5 CVE: CVE-2015-3247 Description: Updated spice packages fix security vulnerability: A race condition flaw, leading to a heap-based memory corruption, was found in spice's worker_update_monitors_config() function, which runs under the QEMU-KVM context on the host. A user in a guest could leverage this flaw to crash the host QEMU-KVM process or, possibly, execute arbitrary code with the privileges of the host QEMU-KVM process (CVE-2015-3247). References: - https://bugs.mageia.org/show_bug.cgi?id=16700 - https://rhn.redhat.com/errata/RHSA-2015-1714.html - http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-3247 SRPMS: - 4/core/spice-0.12.4-4.1.mga4 - 5/core/spice-0.12.5-2.1.mga5