Vulnerability Bulletins

DSA-3354 spice - security update

   
Affected software Debian
 
Frediano Ziglio of Red Hat discovered a race condition flaw in spicesworker_update_monitors_config() function, leading to a heap-based memorycorruption. A malicious user in a guest can take advantage of this flawto cause a denial of service (QEMU process crash) or, potentiallyexecute arbitrary code on the host with the privileges of the hostingQEMU process.

More info:

https://www.debian.org/security/2015/dsa-3354