ISOMAN

CVE

CVE-2015-5260

Heap-based buffer overflow in SPICE before 0.12.6 allows guest OS users to cause a denial of service (heap-based memory corruption and QEMU-KVM crash) or possibly execute arbitrary code on the host via QXL commands related to the surface_id parameter.

Severity
HIGH
CVSS
7.8
Published
Modified

Linked Releases

References

  1. http://lists.freedesktop.org/archives/spice-devel/2015-October/022191.html
  2. http://rhn.redhat.com/errata/RHSA-2015-1889.html
  3. http://rhn.redhat.com/errata/RHSA-2015-1890.html
  4. http://www.debian.org/security/2015/dsa-3371
  5. http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html
  6. http://www.securityfocus.com/bid/77019
  7. http://www.securitytracker.com/id/1033753
  8. http://www.ubuntu.com/usn/USN-2766-1
  9. https://bugzilla.redhat.com/show_bug.cgi?id=1260822
  10. https://security.gentoo.org/glsa/201606-05
  11. http://lists.freedesktop.org/archives/spice-devel/2015-October/022191.html
  12. http://rhn.redhat.com/errata/RHSA-2015-1889.html
  13. http://rhn.redhat.com/errata/RHSA-2015-1890.html
  14. http://www.debian.org/security/2015/dsa-3371
  15. http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html
  16. http://www.securityfocus.com/bid/77019
  17. http://www.securitytracker.com/id/1033753
  18. http://www.ubuntu.com/usn/USN-2766-1
  19. https://bugzilla.redhat.com/show_bug.cgi?id=1260822
  20. https://security.gentoo.org/glsa/201606-05