Red Hat Bugzilla – Bug 568701
CVE-2010-0429 libspice: Relying on guest provided data structures to indicate memory allocation
Last modified: 2016-04-26 23:33:29 EDT
Izik Eidus found a bug in QEMU that allows priviledged guest user to force QEMU process on the host to issue free() and/or malloc() calls at addresses controlled by the guest user. The bug is in QXL/libspice code.
This issue has been addressed in following products: Red Hat Enterprise Linux 5 Via RHSA-2010:0633 https://rhn.redhat.com/errata/RHSA-2010-0633.html
This issue has been addressed in following products: Red Hat Enterprise Virtualization for RHEL-5 Via RHSA-2010:0622 https://rhn.redhat.com/errata/RHSA-2010-0622.html