Your submission was sent successfully! Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!Close

CVE-2013-4282

Published: 2 November 2013

Stack-based buffer overflow in the reds_handle_ticket function in server/reds.c in SPICE 0.12.0 allows remote attackers to cause a denial of service (crash) via a long password in a SPICE ticket.

Priority

Medium

Status

Package Release Status
spice
Launchpad, Ubuntu, Debian
lucid Does not exist

precise Ignored
(end of life)
quantal Ignored
(end of life)
raring
Released (0.12.2-0nocelt2expubuntu1.2)
saucy
Released (0.12.4-0nocelt1ubuntu0.1)
trusty
Released (0.12.4-0nocelt1.1ubuntu1)
upstream
Released (0.12.4-0nocelt2)
utopic
Released (0.12.4-0nocelt1.1ubuntu1)
wily
Released (0.12.4-0nocelt1.1ubuntu1)
xenial
Released (0.12.4-0nocelt1.1ubuntu1)
yakkety
Released (0.12.4-0nocelt1.1ubuntu1)
zesty
Released (0.12.4-0nocelt1.1ubuntu1)
vivid
Released (0.12.4-0nocelt1.1ubuntu1)
Patches:
upstream: http://cgit.freedesktop.org/spice/spice/commit/?id=8af619009660b24e0b41ad26b30289eea288fcc2