Startseite ▼ Bookkeeping
Online ▼ Sicherheits
Überprüfungs ▼
Verwaltetes
DNS ▼
Info
Bestellen/Erneuern
FAQ
AUP
Dynamic DNS Clients
Domaine konfigurieren Dyanmic DNS Update Password Netzwerk
Überwachung ▼
Enterprise
Erweiterte
Standard
Gratis Test
FAQ
Preis/Funktionszusammenfassung
Bestellen
Beispiele
Konfigurieren/Status Alarm Profile | |||
Test Kennung: | 1.3.6.1.4.1.25623.1.0.890825 |
Kategorie: | Debian Local Security Checks |
Titel: | Debian LTS: Security Advisory for spice (DLA-825-1) |
Zusammenfassung: | Several vulnerabilities were discovered in spice, a SPICE protocol;client and server library. The Common Vulnerabilities and Exposures;project identifies the following problems:;;CVE-2016-9577;;Frediano Ziglio of Red Hat discovered a buffer overflow;vulnerability in the main_channel_alloc_msg_rcv_buf function. An;authenticated attacker can take advantage of this flaw to cause a;denial of service (spice server crash), or possibly, execute;arbitrary code.;;CVE-2016-9578;;Frediano Ziglio of Red Hat discovered that spice does not properly;validate incoming messages. An attacker able to connect to the;spice server could send crafted messages which would cause the;process to crash. |
Beschreibung: | Summary: Several vulnerabilities were discovered in spice, a SPICE protocol client and server library. The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2016-9577 Frediano Ziglio of Red Hat discovered a buffer overflow vulnerability in the main_channel_alloc_msg_rcv_buf function. An authenticated attacker can take advantage of this flaw to cause a denial of service (spice server crash), or possibly, execute arbitrary code. CVE-2016-9578 Frediano Ziglio of Red Hat discovered that spice does not properly validate incoming messages. An attacker able to connect to the spice server could send crafted messages which would cause the process to crash. Affected Software/OS: spice on Debian Linux Solution: For Debian 7 'Wheezy', these problems have been fixed in version 0.11.0-1+deb7u4. We recommend that you upgrade your spice packages. CVSS Score: 6.5 CVSS Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P |
Querverweis: |
Common Vulnerability Exposure (CVE) ID: CVE-2016-9577 BugTraq ID: 96040 http://www.securityfocus.com/bid/96040 Debian Security Information: DSA-3790 (Google Search) https://www.debian.org/security/2017/dsa-3790 RedHat Security Advisories: RHSA-2017:0253 http://rhn.redhat.com/errata/RHSA-2017-0253.html RedHat Security Advisories: RHSA-2017:0254 https://access.redhat.com/errata/RHSA-2017:0254 RedHat Security Advisories: RHSA-2017:0549 http://rhn.redhat.com/errata/RHSA-2017-0549.html RedHat Security Advisories: RHSA-2017:0552 https://access.redhat.com/errata/RHSA-2017:0552 Common Vulnerability Exposure (CVE) ID: CVE-2016-9578 BugTraq ID: 96118 http://www.securityfocus.com/bid/96118 |
Copyright | Copyright (C) 2018 Greenbone Networks GmbH http://greenbone.net |
Dies ist nur einer von 99761 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus. Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten. |