Warning message

This translation is outdated. For the most up-to-date information, please refer to the English version.

CVE-2016-0749

Impact:
Important
Public Date:
2016-06-06
CWE:
CWE-131->CWE-122
Bugzilla:
1300646: CVE-2016-0749 spice: heap-based memory corruption within smartcard handling
A memory allocation flaw, leading to a heap-based buffer overflow, was found in spice's smartcard interaction, which runs under the QEMU-KVM context on the host. A user connecting to a guest VM using spice could potentially use this flaw to crash the QEMU-KVM process or execute arbitrary code with the privileges of the host's QEMU-KVM process.

Find out more about CVE-2016-0749 from the MITRE CVE dictionary dictionary and NIST NVD.

CVSS v2 metrics

Base Score 6.8
Base Metrics AV:N/AC:M/Au:N/C:P/I:P/A:P
Access Vector Network
Access Complexity Medium
Authentication None
Confidentiality Impact Partial
Integrity Impact Partial
Availability Impact Partial

Find out more about Red Hat support for the Common Vulnerability Scoring System (CVSS).

Red Hat Security Errata

Platform Errata Release Date
Red Hat Enterprise Linux 6 (spice-server) RHSA-2016:1204 2016-06-06
Red Hat Enterprise Linux 7 (spice) RHSA-2016:1205 2016-06-06

Affected Packages State

Platform Package State
RHEV Manager 3 rhev-hypervisor Affected

Acknowledgements

This issue was discovered by Jing Zhao (Red Hat).

Last Modified
Close

Welcome! Check out the Getting Started with Red Hat page for quick tours and guides for common tasks.