UbuntuUpdates.org

Bugs fixes in "spice"

Origin Bug number Title Date fixed
Launchpad 1874054 fail to resize with qxl 2020-04-29
Launchpad 1874054 fail to resize with qxl 2020-04-29
CVE CVE-2019-3813 Off-by-one error in array access in spice/server/memslot.c 2019-01-30
CVE CVE-2019-3813 Off-by-one error in array access in spice/server/memslot.c 2019-01-28
CVE CVE-2019-3813 Off-by-one error in array access in spice/server/memslot.c 2019-01-28
CVE CVE-2019-3813 Off-by-one error in array access in spice/server/memslot.c 2019-01-28
CVE CVE-2018-10873 A vulnerability was discovered in SPICE before version 0.14.1 where the generated code used for demarshalling messages lacked sufficient bounds check 2018-08-22
CVE CVE-2018-10873 A vulnerability was discovered in SPICE before version 0.14.1 where the generated code used for demarshalling messages lacked sufficient bounds check 2018-08-22
CVE CVE-2017-12194 A flaw was found in the way spice-client processed certain messages sent from the server. An attacker, having control of malicious spice-server, coul 2018-05-23
CVE CVE-2017-12194 A flaw was found in the way spice-client processed certain messages sent from the server. An attacker, having control of malicious spice-server, coul 2018-05-23
CVE CVE-2017-7506 spice versions though 0.13 are vulnerable to out-of-bounds memory ... 2017-07-19
CVE CVE-2017-7506 spice versions though 0.13 are vulnerable to out-of-bounds memory ... 2017-07-19
CVE CVE-2016-2150 SPICE allows local guest OS users to read from or write to arbitrary host memory locations via crafted primary surface parameters, a similar issue to 2016-06-21
CVE CVE-2016-0749 The smartcard interaction in SPICE allows remote attackers to cause a denial of service (QEMU-KVM process crash) or possibly execute arbitrary code v 2016-06-21
CVE CVE-2016-2150 SPICE allows local guest OS users to read from or write to arbitrary host memory locations via crafted primary surface parameters, a similar issue to 2016-06-21
CVE CVE-2016-0749 The smartcard interaction in SPICE allows remote attackers to cause a denial of service (QEMU-KVM process crash) or possibly execute arbitrary code v 2016-06-21



About   -   Send Feedback to @ubuntu_updates