Package "spice-vdagent"
Name: |
spice-vdagent
|
Description: |
Spice agent for Linux
|
Latest version: |
0.19.0-2ubuntu0.2 |
Release: |
focal (20.04) |
Level: |
security |
Repository: |
main |
Homepage: |
http://www.spice-space.org/ |
Links
Download "spice-vdagent"
Other versions of "spice-vdagent" in Focal
Changelog
spice-vdagent (0.19.0-2ubuntu0.2) focal-security; urgency=medium
* SECURITY UPDATE: Memory DoS via Arbitrary Entries in active_xfers Hash
Table
- debian/patches/CVE-2020-25650-1.patch: avoid agents allocating file
transfers in src/vdagentd/vdagentd.c.
- debian/patches/CVE-2020-25650-2.patch: avoid uncontrolled
active_xfers allocations in src/vdagentd/vdagentd.c.
- CVE-2020-25650
* SECURITY UPDATE: Possible File Transfer DoS and Information Leak via
active_xfers Hash Map
- debian/patches/CVE-2020-25651-1.patch: cleanup active_xfers when the
client disconnects in src/vdagentd/vdagentd.c.
- debian/patches/CVE-2020-25651-2.patch: do not allow using an already
used file-xfer id in src/vdagentd/vdagentd.c.
- CVE-2020-25651
* SECURITY UPDATE: Possibility to Exhaust File Descriptors in vdagentd
- debian/patches/CVE-2020-25652-1.patch: avoid unlimited agent
connections in src/udscs.c.
- debian/patches/CVE-2020-25652-2.patch: limit number of agents per
session to 1 in src/vdagentd/vdagentd.c.
- CVE-2020-25652
* SECURITY UPDATE: UNIX Domain Socket Peer PID Retrieved via SO_PEERCRED
is Subject to Race Condition
- debian/patches/CVE-2020-25653-1.patch: avoid user session hijacking
in src/udscs.c, src/udscs.h, src/vdagentd/vdagentd.c.
- debian/patches/CVE-2020-25653-2.patch: better check for sessions in
src/vdagentd/console-kit.c, src/vdagentd/dummy-session-info.c,
src/vdagentd/session-info.h, src/vdagentd/systemd-login.c,
src/vdagentd/vdagentd.c.
- CVE-2020-25653
* Additional fixes:
- debian/patches/CVE-2020-2565x-1.patch: avoid calling chmod in
src/vdagentd/vdagentd.c.
-- Marc Deslauriers <email address hidden> Mon, 02 Nov 2020 16:27:12 -0500
|
CVE-2020-25650 |
Memory DoS via Arbitrary Entries in active_xfers Hash Table |
CVE-2020-25651 |
Possible File Transfer DoS and Information Leak via active_xfers Hash Map |
CVE-2020-25652 |
Possibility to Exhaust File Descriptors in vdagentd |
CVE-2020-25653 |
UNIX Doman Socket Peer PID Retrieved via SO_PEERCRED is Subject to Race Condition |
CVE-2020-2565 |
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Consolidation Infrastructure). The supported version that is affected is 11 |
|
About
-
Send Feedback to @ubuntu_updates