{"id":"MGASA-2014-0022","summary":"Updated spice packages fix a security vulnerability","details":"Updated spice packages fix security vulnerability:\n\nA stack-based buffer overflow flaw was found in the way the\nreds_handle_ticket() function in the spice-server library handled\ndecryption of ticket data provided by the client. A remote user able to\ninitiate a SPICE connection to an application acting as a SPICE server\ncould use this flaw to crash the application (CVE-2013-4282).\n","modified":"2026-04-16T06:25:46.897985590Z","published":"2014-01-21T16:20:58Z","upstream":["CVE-2013-4282"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2014-0022.html"},{"type":"WEB","url":"https://rhn.redhat.com/errata/RHSA-2013-1473.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=12266"}],"affected":[{"package":{"name":"spice","ecosystem":"Mageia:3","purl":"pkg:rpm/mageia/spice?arch=source&distro=mageia-3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.12.2-5.2.mga3"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2014-0022.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}