[3.9] spice: Off-by-one error in array access in spice/server/memslot.c (CVE-2019-3813)
spice versions 0.5.2 through 0.14.1 are vulnerable to an out-of-bounds
read
due to an off-by-one error in memslot_get_virt. This may lead to a
denial-of-service, or, in the worst case, code-execution by
unauthenticated
attackers.
Fixed In Version:
spice 0.14.2
References:
https://www.openwall.com/lists/oss-security/2019/01/28/2
(from redmine: issue id 9940, created on 2019-01-29, closed on 2019-02-14)
- Relations:
- parent #9939 (closed)
- Changesets:
- Revision 82ef1421 on 2019-01-30T16:04:59Z:
main/spice: security fix (CVE-2019-3813)
Fixes #9940