Wind River Support Network

HomeDefectsLIN9-4799
Fixed

LIN9-4799 : Security Advisory - spice - CVE-2017-7506

Created: Jul 27, 2017    Updated: May 18, 2019
Resolved Date: Apr 19, 2019
Found In Version: 9.0.0.8
Fix Version: 9.0.0.21
Severity: Standard
Applicable for: Wind River Linux 9
Component/s: Userspace

Description

spice versions though 0.13 are vulnerable to out-of-bounds memory access when processing specially crafted messages from authenticated attacker to the spice server resulting into crash and/or server memory leak.

https://nvd.nist.gov/vuln/detail/CVE-2017-7506

CVEs


Live chat
Online