CVSS2
Attack Vector
LOCAL
Attack Complexity
MEDIUM
Authentication
SINGLE
Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
AV:L/AC:M/Au:S/C:C/I:C/A:C
EPSS
Percentile
20.8%
CentOS Errata and Security Advisory CESA-2010:0633
The Simple Protocol for Independent Computing Environments (SPICE) is a
remote display protocol used in Red Hat Enterprise Linux for viewing
virtualized guests running on the Kernel-based Virtual Machine (KVM)
hypervisor, or on Red Hat Enterprise Virtualization Hypervisor.
It was found that the libspice component of QEMU-KVM on the host did not
validate all pointers provided from a guest system’s QXL graphics card
driver. A privileged guest user could use this flaw to cause the host to
dereference an invalid pointer, causing the guest to crash (denial of
service) or, possibly, resulting in the privileged guest user escalating
their privileges on the host. (CVE-2010-0428)
It was found that the libspice component of QEMU-KVM on the host could be
forced to perform certain memory management operations on memory addresses
controlled by a guest. A privileged guest user could use this flaw to crash
the guest (denial of service) or, possibly, escalate their privileges on
the host. (CVE-2010-0429)
All qspice users should upgrade to these updated packages, which contain
backported patches to correct these issues.
Merged security bulletin from advisories:
https://lists.centos.org/pipermail/centos-announce/2010-August/079117.html
Affected packages:
qspice
qspice-libs
qspice-libs-devel
Upstream details at:
https://access.redhat.com/errata/RHSA-2010:0633
OS | Version | Architecture | Package | Version | Filename |
---|---|---|---|---|---|
CentOS | 5 | x86_64 | qspice | < 0.3.0-54.el5_5.2 | qspice-0.3.0-54.el5_5.2.x86_64.rpm |
CentOS | 5 | x86_64 | qspice-libs | < 0.3.0-54.el5_5.2 | qspice-libs-0.3.0-54.el5_5.2.x86_64.rpm |
CentOS | 5 | x86_64 | qspice-libs-devel | < 0.3.0-54.el5_5.2 | qspice-libs-devel-0.3.0-54.el5_5.2.x86_64.rpm |