2024-12-12 21:07:30 +00:00

104 lines
3.5 KiB
JSON

{
"Definition": [
{
"ID": "oval:org.altlinux.errata:def:20151864",
"Version": "oval:org.altlinux.errata:def:20151864",
"Class": "patch",
"Metadata": {
"Title": "ALT-PU-2015-1864: package `SPICE` update to version 0.12.6-alt1",
"AffectedList": [
{
"Family": "unix",
"Platforms": [
"ALT Linux branch c9f2"
],
"Products": [
"ALT SPWorkstation",
"ALT SPServer"
]
}
],
"References": [
{
"RefID": "ALT-PU-2015-1864",
"RefURL": "https://errata.altlinux.org/ALT-PU-2015-1864",
"Source": "ALTPU"
},
{
"RefID": "CVE-2015-5260",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2015-5260",
"Source": "CVE"
},
{
"RefID": "CVE-2015-5261",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2015-5261",
"Source": "CVE"
}
],
"Description": "This update upgrades SPICE to version 0.12.6-alt1. \nSecurity Fix(es):\n\n * CVE-2015-5260: Heap-based buffer overflow in SPICE before 0.12.6 allows guest OS users to cause a denial of service (heap-based memory corruption and QEMU-KVM crash) or possibly execute arbitrary code on the host via QXL commands related to the surface_id parameter.\n\n * CVE-2015-5261: Heap-based buffer overflow in SPICE before 0.12.6 allows guest OS users to read and write to arbitrary memory locations on the host via guest QXL commands related to surface creation.",
"Advisory": {
"From": "errata.altlinux.org",
"Severity": "High",
"Rights": "Copyright 2024 BaseALT Ltd.",
"Issued": {
"Date": "2015-10-12"
},
"Updated": {
"Date": "2015-10-12"
},
"BDUs": null,
"CVEs": [
{
"ID": "CVE-2015-5260",
"CVSS": "AV:L/AC:L/Au:N/C:C/I:C/A:C",
"CVSS3": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"CWE": "CWE-119",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2015-5260",
"Impact": "High",
"Public": "20160607"
},
{
"ID": "CVE-2015-5261",
"CVSS": "AV:L/AC:L/Au:N/C:P/I:P/A:N",
"CVSS3": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
"CWE": "CWE-119",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2015-5261",
"Impact": "High",
"Public": "20160607"
}
],
"AffectedCPEs": {
"CPEs": [
"cpe:/o:alt:spworkstation:8.4",
"cpe:/o:alt:spserver:8.4"
]
}
}
},
"Criteria": {
"Operator": "AND",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:4001",
"Comment": "ALT Linux must be installed"
}
],
"Criterias": [
{
"Operator": "OR",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:20151864001",
"Comment": "libspice-server is earlier than 0:0.12.6-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20151864002",
"Comment": "libspice-server-devel is earlier than 0:0.12.6-alt1"
}
]
}
]
}
}
]
}