Debian Security Advisory 3354-1

Discussion in 'News Aggregator' started by Packet Storm, 10 Sep 2015.

  1. Packet Storm

    Packet Storm Guest

    Debian Linux Security Advisory 3354-1 - Frediano Ziglio of Red Hat discovered a race condition flaw in spice's worker_update_monitors_config() function, leading to a heap-based memory corruption. A malicious user in a guest can take advantage of this flaw to cause a denial of service (QEMU process crash) or, potentially execute arbitrary code on the host with the privileges of the hosting QEMU process.

    Continue reading...
     

Share This Page

Loading...