FS#71803 - [usbredir] [Security] arbitrary code execution (CVE-2021-3700)
Attached to Project:
Community Packages
Opened by Jonas Witschel (diabonas) - Wednesday, 11 August 2021, 21:12 GMT
Last edited by Jonas Witschel (diabonas) - Sunday, 22 August 2021, 10:44 GMT
Opened by Jonas Witschel (diabonas) - Wednesday, 11 August 2021, 21:12 GMT
Last edited by Jonas Witschel (diabonas) - Sunday, 22 August 2021, 10:44 GMT
|
Details
Summary
======= The package usbredir is vulnerable to arbitrary code execution via CVE-2021-3700. Guidance ======== Upgrading to the latest version 0.11.0 (https://gitlab.freedesktop.org/spice/usbredir/-/tags/usbredir-0.11.0) fixes the issue. References ========== https://security.archlinux.org/AVG-2279 https://bugzilla.redhat.com/show_bug.cgi?id=1992830 https://gitlab.freedesktop.org/spice/usbredir/-/commit/03c519ff5831ba75120e00ebebbf1d5a1f7220ab |
This task depends upon
Closed by Jonas Witschel (diabonas)
Sunday, 22 August 2021, 10:44 GMT
Reason for closing: Fixed
Additional comments about closing: usbredir 0.11.0-1
Sunday, 22 August 2021, 10:44 GMT
Reason for closing: Fixed
Additional comments about closing: usbredir 0.11.0-1