[El-errata] ELSA-2013-1473 Important: Oracle Linux 6 spice-server security update

Errata Announcements for Oracle Linux el-errata at oss.oracle.com
Tue Oct 29 18:07:51 PDT 2013


Oracle Linux Security Advisory ELSA-2013-1473

https://rhn.redhat.com/errata/RHSA-2013-1473.html

The following updated rpms for Oracle Linux 6 have been uploaded to the 
Unbreakable Linux Network:


x86_64:
spice-server-0.12.0-12.el6_4.5.x86_64.rpm
spice-server-devel-0.12.0-12.el6_4.5.x86_64.rpm


SRPMS:
http://oss.oracle.com/ol6/SRPMS-updates/spice-server-0.12.0-12.el6_4.5.src.rpm



Description of changes:

[0.12.0-12.5]
- Fix issue with error-handling of RSA_private_decrypt() in previous patch
   Related: CVE-2013-4282

[0.12.0-12.el6_4.4]
- Fix buffer overflow when decrypting client SPICE ticket
   Resolves: CVE-2013-4282





More information about the El-errata mailing list