FS#54808 - [spice] Backporting security fixes for CVE-2017-7506

Attached to Project: Arch Linux
Opened by Remi Gacogne (rgacogne) - Friday, 14 July 2017, 18:52 GMT
Last edited by Jan de Groot (JGC) - Sunday, 13 August 2017, 23:20 GMT
Task Type Bug Report
Category Security
Status Closed
Assigned To Tobias Powalowski (tpowa)
Architecture All
Severity High
Priority Normal
Reported Version
Due in Version Undecided
Due Date Undecided
Percent Complete 100%
Votes 0
Private No



A security issue issue [1] has been found in spice <= 0.12.8, possibly leading to (authenticated) remote code execution.
Three patches [2][3][4] have been committed to the 0.12 branch to fix this issue, so it would be nice if we could backport them until a new version is released.
I see that some patches were previously added on that same branch after 0.12.8, all of them looking like security fixes, so perhaps we should just switch to the current git head of that branch?


[1]: https://bugzilla.redhat.com/show_bug.cgi?id=1452606
[2]: https://cgit.freedesktop.org/spice/spice/commit/?h=0.12&id=f1e7ec03e26ab6b8ca9b7ec060846a5b706a963d
[3]: https://cgit.freedesktop.org/spice/spice/commit/?h=0.12&id=ec6229c79abe05d731953df5f7e9a05ec9f6df79
[4]: https://cgit.freedesktop.org/spice/spice/commit/?h=0.12&id=a957a90baf2c62d31f3547e56bba7d0e812d2331
This task depends upon

Closed by  Jan de Groot (JGC)
Sunday, 13 August 2017, 23:20 GMT
Reason for closing:  Fixed