Bug#898503: spice-gtk: CVE-2017-12194: Integer overflows causing buffer overflows in spice-client

2018-07-19 Thread Laurent Bigonville
Package: src:spice-gtk Followup-For: Bug #898503 Hi, This seems to be fixed in 0.35 release, could you please update? (It requires a newer version of spice-protocol first) Kind regards, Laurent Bigonville -- System Information: Debian Release: buster/sid APT prefers unstable-debug APT

Bug#898503: spice-gtk: CVE-2017-12194: Integer overflows causing buffer overflows in spice-client

2018-05-12 Thread Salvatore Bonaccorso
Control: tags -1 + patch Attaching as well the two proposed patches (and which make the testcase pass). Regards, Salvatore >From 78b54cbaa064f0ac94af114edb54fca3b365430d Mon Sep 17 00:00:00 2001 From: Frediano Ziglio Date: Fri, 19 Jun 2015 14:42:54 +0100 Subject: [PATCH

Bug#898503: spice-gtk: CVE-2017-12194: Integer overflows causing buffer overflows in spice-client

2018-05-12 Thread Salvatore Bonaccorso
Source: spice-gtk Version: 0.25-1 Severity: important Tags: security upstream Hi, The following vulnerability was published for spice-gtk. CVE-2017-12194[0]: | A flaw was found in the way spice-client processed certain messages | sent from the server. An attacker, having control of malicious |