Vulnerability Bulletins |
DSA-3354 spice - security update |
|
| Affected software | Debian |
|
Frediano Ziglio of Red Hat discovered a race condition flaw in spicesworker_update_monitors_config() function, leading to a heap-based memorycorruption. A malicious user in a guest can take advantage of this flawto cause a denial of service (QEMU process crash) or, potentiallyexecute arbitrary code on the host with the privileges of the hostingQEMU process. More info: https://www.debian.org/security/2015/dsa-3354 |
|






