SB2017031634 - RHEV 4 update for rhevm-appliance



SB2017031634 - RHEV 4 update for rhevm-appliance

Published: March 16, 2017 Updated: April 24, 2025

Security Bulletin ID SB2017031634
Severity
High
Patch available
YES
Number of vulnerabilities 2
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 50% Medium 50%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 2 secuirty vulnerabilities.


1) Buffer overflow (CVE-ID: CVE-2016-9577)

The vulnerability allows a remote authenticated user to execute arbitrary code.

A vulnerability was discovered in SPICE before 0.13.90 in the server's protocol handling. An authenticated attacker could send crafted messages to the SPICE server causing a heap overflow leading to a crash or possible code execution.


2) Input validation error (CVE-ID: CVE-2016-9578)

The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.

A vulnerability was discovered in SPICE before 0.13.90 in the server's protocol handling. An attacker able to connect to the SPICE server could send crafted messages which would cause the process to crash.


Remediation

Install update from vendor's website.