Wind River Support Network

HomeDefectsLIN8-7206
Fixed

LIN8-7206 : Security Advisory - spice - CVE-2017-7506

Created: Jul 27, 2017    Updated: Apr 2, 2019
Resolved Date: Apr 1, 2019
Found In Version: 8.0.0.19
Fix Version: 8.0.0.30
Severity: Standard
Applicable for: Wind River Linux 8
Component/s: Userspace

Description

spice versions though 0.13 are vulnerable to out-of-bounds memory access when processing specially crafted messages from authenticated attacker to the spice server resulting into crash and/or server memory leak.

https://nvd.nist.gov/vuln/detail/CVE-2017-7506

CVEs


Live chat
Online