CVE-2015-3247

Publication date 3 September 2015

Last updated 24 July 2024


Ubuntu priority

Race condition in the worker_update_monitors_config function in SPICE 0.12.4 allows a remote authenticated guest user to cause a denial of service (heap-based memory corruption and QEMU-KVM crash) or possibly execute arbitrary code on the host via unspecified vectors.

Status

Package Ubuntu Release Status
spice 15.04 vivid
Fixed 0.12.5-1ubuntu0.1
14.04 LTS trusty
Fixed 0.12.4-0nocelt2ubuntu1.1
12.04 LTS precise
Not affected

References

Related Ubuntu Security Notices (USN)

Other references