FS#54808 - [spice] Backporting security fixes for CVE-2017-7506
Attached to Project:
Arch Linux
Opened by Remi Gacogne (rgacogne) - Friday, 14 July 2017, 18:52 GMT
Last edited by Jan de Groot (JGC) - Sunday, 13 August 2017, 23:20 GMT
Opened by Remi Gacogne (rgacogne) - Friday, 14 July 2017, 18:52 GMT
Last edited by Jan de Groot (JGC) - Sunday, 13 August 2017, 23:20 GMT
|
Details
Hi,
A security issue issue [1] has been found in spice <= 0.12.8, possibly leading to (authenticated) remote code execution. Three patches [2][3][4] have been committed to the 0.12 branch to fix this issue, so it would be nice if we could backport them until a new version is released. I see that some patches were previously added on that same branch after 0.12.8, all of them looking like security fixes, so perhaps we should just switch to the current git head of that branch? Thanks! [1]: https://bugzilla.redhat.com/show_bug.cgi?id=1452606 [2]: https://cgit.freedesktop.org/spice/spice/commit/?h=0.12&id=f1e7ec03e26ab6b8ca9b7ec060846a5b706a963d [3]: https://cgit.freedesktop.org/spice/spice/commit/?h=0.12&id=ec6229c79abe05d731953df5f7e9a05ec9f6df79 [4]: https://cgit.freedesktop.org/spice/spice/commit/?h=0.12&id=a957a90baf2c62d31f3547e56bba7d0e812d2331 |
This task depends upon