spice-server-0.12.0-12.AXS4.3

エラータID: AXSA:2013-596:04

Release date: 
Wednesday, September 11, 2013 - 10:56
Subject: 
spice-server-0.12.0-12.AXS4.3
Affected Channels: 
Asianux Server 4 for x86_64
Severity: 
High
Description: 

The Simple Protocol for Independent Computing Environments (SPICE) is a remote display system built for virtual environments which allows you to view a computing 'desktop' environment not only on the machine where it is running, but from anywhere on the Internet and from a wide variety of machine architectures.

This package contains the runtime libraries for any application that wishes to be a SPICE server.

Security issues fixed with this release:

• CVE-2013-4130
The (1) red_channel_pipes_add_type and (2) red_channel_pipes_add_empty_msg functions in server/red_channel.c in SPICE before 0.12.4 do not properly perform ring loops, which might allow remote attackers to cause a denial of service (reachable assertion and server exit) by triggering a network error.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. spice-server-0.12.0-12.AXS4.3.src.rpm
    MD5: 03d258b180975e1ad6dccc49d2ba99d7
    SHA-256: 0069e4894c48cd5b10266b5b05c6bca84973e18608c506b41cce6770c26e9ba7
    Size: 1.50 MB

Asianux Server 4 for x86_64
  1. spice-server-0.12.0-12.AXS4.3.x86_64.rpm
    MD5: 1905a3fd3ebd859f4272c95fcfe0d38f
    SHA-256: 15e7d43db1836b845b54ec8809039b9827cd36e28f86813d40d2c940f3759812
    Size: 325.12 kB