Red Hat Bugzilla – Bug 1598234
CVE-2018-10893 spice-client: Insufficient encoding checks for LZ can cause different integer/buffer overflows
Last modified: 2018-10-15 05:45:39 EDT
A flaw was found in spice-client. An improper check on LZ images sent by the server could lead to an integer/buffer overflows on the client. References: https://bugzilla.redhat.com/show_bug.cgi?id=1594904
Created mingw-spice-gtk tracking bugs for this issue: Affects: fedora-all [bug 1598236] Created spice-gtk tracking bugs for this issue: Affects: fedora-all [bug 1598235]
Hi Laura Since the Red Hat reference is not accessible, are there any details available for this issue? Is the issue adressed already? Regards, Salvatore
Acknowledgments: Name: Frediano Ziglio (Red Hat)
Created attachment 1459094 [details] First patch
Created attachment 1459095 [details] Second patch
References: https://lists.freedesktop.org/archives/spice-devel/2018-July/044489.html
*** Bug 1594904 has been marked as a duplicate of this bug. ***