{"id":"MGASA-2017-0239","summary":"Updated spice packages fix security vulnerability","details":"A vulnerability was discovered in spice, in the server's protocol handling. An\nauthenticated attacker could send specially crafted messages to the spice\nserver, causing out-of-bounds memory accesses leading to parts of server memory\nbeing leaked or a crash (CVE-2017-7506).\n\nThe Mageia 5 package has been patched to fix this issue.  The Mageia 6 package\nhas been updated to version 0.13.90, containing fixes for this and several other\nissues.\n","modified":"2026-04-16T06:24:03.515248316Z","published":"2017-08-03T19:05:47Z","upstream":["CVE-2017-7506"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2017-0239.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=21230"},{"type":"WEB","url":"https://cgit.freedesktop.org/spice/spice/tree/NEWS?id=34dff543bef7a5201f41c72353a65840bd37c275"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1452606"},{"type":"WEB","url":"https://www.debian.org/security/2017/dsa-3907"},{"type":"WEB","url":"https://lists.opensuse.org/opensuse-security-announce/2017-07/msg00013.html"}],"affected":[{"package":{"name":"spice","ecosystem":"Mageia:5","purl":"pkg:rpm/mageia/spice?arch=source&distro=mageia-5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.12.5-2.5.mga5"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2017-0239.json"}},{"package":{"name":"spice","ecosystem":"Mageia:6","purl":"pkg:rpm/mageia/spice?arch=source&distro=mageia-6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.13.90-1.mga6"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2017-0239.json"}},{"package":{"name":"spice-protocol","ecosystem":"Mageia:6","purl":"pkg:rpm/mageia/spice-protocol?arch=source&distro=mageia-6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.12.13-1.mga6"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2017-0239.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}