USN-3751-1: Spice vulnerability
22 August 2018
Spice could be made to crash if it received specially crafted network traffic.
Releases
Packages
- spice - SPICE protocol client and server library
- spice-protocol - SPICE protocol headers
Details
It was discovered that Spice incorrectly handled certain messages.
An attacker could possibly use this issue to cause a denial of service.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 18.04
Ubuntu 16.04
Ubuntu 14.04
After a standard system update you need to restart qemu guests to make all
the necessary changes.