Bug 1596008 (CVE-2018-10873)
| Summary: | CVE-2018-10873 spice: Missing check in demarshal.py:write_validate_array_item() allows for buffer overflow and denial of service | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | Sam Fowler <sfowler> |
| Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
| Status: | CLOSED ERRATA | QA Contact: | |
| Severity: | high | Docs Contact: | |
| Priority: | high | ||
| Version: | unspecified | CC: | alexl, alon, bmcclain, cfergeau, dblechte, dfediuck, eedri, fziglio, hdegoede, jforbes, kraxel, marcandre.lureau, mgoldboi, michal.skrivanek, mkenneth, rh-spice-bugs, sandmann, sbonazzo, security-response-team, sfowler, sherold, srevivo, tburke, uril, victortoso, ykamay, yozone |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | spice 0.14.1, spice-gtk 0.36 | Doc Type: | If docs needed, set a value |
| Doc Text: |
A vulnerability was discovered in SPICE where the generated code used for demarshalling messages lacked sufficient bounds checks. A malicious client or server, after authentication, could send specially crafted messages to its peer which would result in a crash or, potentially, other impacts.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | 2019-06-10 10:30:53 UTC | Type: | --- |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 1597466, 1597467, 1597468, 1597469, 1597470, 1618554, 1618555 | ||
| Bug Blocks: | 1596011 | ||
|
Description
Sam Fowler
2018-06-28 03:29:37 UTC
Product Bug: https://bugzilla.redhat.com/show_bug.cgi?id=1594772 Acknowledgments: Name: Frediano Ziglio (Red Hat) Upstream patch: https://gitlab.freedesktop.org/spice/spice-common/commit/bb15d4815ab586b4c4a20f4a565970a44824c42c Created spice tracking bugs for this issue: Affects: fedora-all [bug 1618554] This issue has been addressed in the following products: Red Hat Enterprise Linux 6 Via RHSA-2018:2732 https://access.redhat.com/errata/RHSA-2018:2732 This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Via RHSA-2018:2731 https://access.redhat.com/errata/RHSA-2018:2731 This issue has been addressed in the following products: Red Hat Virtualization 4 for Red Hat Enterprise Linux 7 Via RHSA-2018:3470 https://access.redhat.com/errata/RHSA-2018:3470 |