Summary: | <net-misc/spice-gtk-0.34: Denial of Service/RCE vulnerability through malicious messages | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | GLSAMaker/CVETool Bot <glsamaker> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED FIXED | ||
Severity: | normal | CC: | virtualization |
Priority: | Normal | Flags: | stable-bot:
sanity-check+
|
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | B2 [glsa+ cve] | ||
Package list: |
net-misc/spice-gtk-0.34-r2
app-emulation/spice-0.14.0-r1
app-emulation/spice-protocol-0.12.13
|
Runtime testing required: | --- |
Description
GLSAMaker/CVETool Bot
![]() Arches, please stabilize net-misc/spice-gtk-0.34-r2. An automated check of this bug failed - the following atom is unknown: app-emulation/spice-0.14.0 Please verify the atom list. An automated check of this bug succeeded - the previous repoman errors are now resolved. amd64 stable x86 stable This bug's workflow looks stuck. Stabilization is complete, I'm cleaning up. The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=20549bbffcf99fc94c3a0a5a6a80aa4bfcfd1546 commit 20549bbffcf99fc94c3a0a5a6a80aa4bfcfd1546 Author: Virgil Dupras <vdupras@gentoo.org> AuthorDate: 2018-08-07 00:06:32 +0000 Commit: Virgil Dupras <vdupras@gentoo.org> CommitDate: 2018-08-07 00:07:18 +0000 net-misc/spice-gtk: remove vulnerable version Bug: https://bugs.gentoo.org/650878 Package-Manager: Portage-2.3.44, Repoman-2.3.10 net-misc/spice-gtk/Manifest | 1 - .../files/spice-gtk-0.33-sys-sysmacros.h.patch | 44 ------ net-misc/spice-gtk/spice-gtk-0.33-r2.ebuild | 152 --------------------- 3 files changed, 197 deletions(-) This issue was resolved and addressed in GLSA 201811-20 at https://security.gentoo.org/glsa/201811-20 by GLSA coordinator Aaron Bauman (b-man). |