Executive Summary
Summary | |
---|---|
Title | spice-xpi security update |
Informations | |||
---|---|---|---|
Name | RHSA-2011:0426 | First vendor Publication | 2011-04-07 |
Vendor | RedHat | Last vendor Modification | 2011-04-07 |
Severity (Vendor) | Moderate | Revision | 01 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:H/Au:N/C:P/I:P/A:P) | |||
---|---|---|---|
Cvss Base Score | 5.1 | Attack Range | Network |
Cvss Impact Score | 6.4 | Attack Complexity | High |
Cvss Expoit Score | 4.9 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
Problem Description: An updated spice-xpi package that fixes two security issues is now available for Red Hat Enterprise Linux 6. The Red Hat Security Response Team has rated this update as having moderate security impact. Common Vulnerability Scoring System (CVSS) base scores, which give detailed severity ratings, are available for each vulnerability from the CVE links in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Desktop (v. 6) - i386, x86_64 Red Hat Enterprise Linux HPC Node Optional (v. 6) - x86_64 Red Hat Enterprise Linux Server (v. 6) - i386, x86_64 Red Hat Enterprise Linux Workstation (v. 6) - i386, x86_64 3. Description: The Simple Protocol for Independent Computing Environments (SPICE) is a remote display protocol used in Red Hat Enterprise Linux for viewing virtualized guests running on the Kernel-based Virtual Machine (KVM) hypervisor, or on Red Hat Enterprise Virtualization Hypervisor. The spice-xpi package provides a plug-in that allows the SPICE client to run from within Mozilla Firefox. An uninitialized pointer use flaw was found in the SPICE Firefox plug-in. If a user were tricked into visiting a malicious web page with Firefox while the SPICE plug-in was enabled, it could cause Firefox to crash or, possibly, execute arbitrary code with the privileges of the user running Firefox. (CVE-2011-1179) It was found that the SPICE Firefox plug-in used a predictable name for one of its log files. A local attacker could use this flaw to conduct a symbolic link attack, allowing them to overwrite arbitrary files accessible to the user running Firefox. (CVE-2011-0012) Users of spice-xpi should upgrade to this updated package, which contains backported patches to correct these issues. After installing the update, Firefox must be restarted for the changes to take effect. 4. Solution: Before applying this update, make sure all previously-released errata relevant to your system have been applied. This update is available via the Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at https://access.redhat.com/kb/docs/DOC-11259 5. Bugs fixed (http://bugzilla.redhat.com/): 639869 - CVE-2011-0012 spice-xpi: symlink attack on usbrdrctl log file 689931 - CVE-2011-1179 spice-xpi: unitialized pointer writes possible when getting plugin properties |
Original Source
Url : https://rhn.redhat.com/errata/RHSA-2011-0426.html |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
50 % | CWE-119 | Failure to Constrain Operations within the Bounds of a Memory Buffer |
50 % | CWE-59 | Improper Link Resolution Before File Access ('Link Following') |
OVAL Definitions
Definition Id: oval:org.mitre.oval:def:21524 | |||
Oval ID: | oval:org.mitre.oval:def:21524 | ||
Title: | RHSA-2011:0426: spice-xpi security update (Moderate) | ||
Description: | The SPICE Firefox plug-in (spice-xpi) 2.4, 2.3, 2.2, and possibly other versions allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to (1) plugin/nsScriptablePeer.cpp and (2) plugin/plugin.cpp, which trigger multiple uses of an uninitialized pointer. | ||
Family: | unix | Class: | patch |
Reference(s): | RHSA-2011:0426-01 CVE-2011-0012 CVE-2011-1179 | Version: | 29 |
Platform(s): | Red Hat Enterprise Linux 6 | Product(s): | spice-xpi |
Definition Synopsis: | |||
Definition Id: oval:org.mitre.oval:def:21691 | |||
Oval ID: | oval:org.mitre.oval:def:21691 | ||
Title: | RHSA-2011:0427: spice-xpi security update (Moderate) | ||
Description: | The SPICE Firefox plug-in (spice-xpi) 2.4, 2.3, 2.2, and possibly other versions allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to (1) plugin/nsScriptablePeer.cpp and (2) plugin/plugin.cpp, which trigger multiple uses of an uninitialized pointer. | ||
Family: | unix | Class: | patch |
Reference(s): | RHSA-2011:0427-01 CESA-2011:0427 CVE-2011-1179 | Version: | 4 |
Platform(s): | Red Hat Enterprise Linux 5 CentOS Linux 5 | Product(s): | spice-xpi |
Definition Synopsis: | |||
Definition Id: oval:org.mitre.oval:def:22805 | |||
Oval ID: | oval:org.mitre.oval:def:22805 | ||
Title: | ELSA-2011:0427: spice-xpi security update (Moderate) | ||
Description: | The SPICE Firefox plug-in (spice-xpi) 2.4, 2.3, 2.2, and possibly other versions allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to (1) plugin/nsScriptablePeer.cpp and (2) plugin/plugin.cpp, which trigger multiple uses of an uninitialized pointer. | ||
Family: | unix | Class: | patch |
Reference(s): | ELSA-2011:0427-01 CVE-2011-1179 | Version: | 6 |
Platform(s): | Oracle Linux 5 | Product(s): | spice-xpi |
Definition Synopsis: | |||
Definition Id: oval:org.mitre.oval:def:23513 | |||
Oval ID: | oval:org.mitre.oval:def:23513 | ||
Title: | ELSA-2011:0426: spice-xpi security update (Moderate) | ||
Description: | The SPICE Firefox plug-in (spice-xpi) 2.4, 2.3, 2.2, and possibly other versions allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to (1) plugin/nsScriptablePeer.cpp and (2) plugin/plugin.cpp, which trigger multiple uses of an uninitialized pointer. | ||
Family: | unix | Class: | patch |
Reference(s): | ELSA-2011:0426-01 CVE-2011-0012 CVE-2011-1179 | Version: | 13 |
Platform(s): | Oracle Linux 6 | Product(s): | spice-xpi |
Definition Synopsis: | |||
Definition Id: oval:org.mitre.oval:def:27548 | |||
Oval ID: | oval:org.mitre.oval:def:27548 | ||
Title: | DEPRECATED: ELSA-2011-0426 -- spice-xpi security update (moderate) | ||
Description: | [2.4-1.el6_0.2] - Fix security vulnerability CVE-2011-0012 (rhbz#639869) Resolves: rhbz#639870 [2.4-1.el6_0.1] - Fix security vulnerability CVE-2011-1179 (rhbz#689931) Resolves: rhbz#689932 | ||
Family: | unix | Class: | patch |
Reference(s): | ELSA-2011-0426 CVE-2011-0012 CVE-2011-1179 | Version: | 4 |
Platform(s): | Oracle Linux 6 | Product(s): | spice-xpi |
Definition Synopsis: | |||
CPE : Common Platform Enumeration
Type | Description | Count |
---|---|---|
Application | 3 |
OpenVAS Exploits
Date | Description |
---|---|
2012-07-30 | Name : CentOS Update for spice-xpi CESA-2011:0427 centos5 x86_64 File : nvt/gb_CESA-2011_0427_spice-xpi_centos5_x86_64.nasl |
2012-06-06 | Name : RedHat Update for spice-xpi RHSA-2011:0426-01 File : nvt/gb_RHSA-2011_0426-01_spice-xpi.nasl |
2011-08-09 | Name : CentOS Update for spice-xpi CESA-2011:0427 centos5 i386 File : nvt/gb_CESA-2011_0427_spice-xpi_centos5_i386.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
73426 | SPICE Plugin for Mozilla Firefox plugin/plugin.cpp.cpp Uninitialized Pointer DoS |
73425 | SPICE Plugin for Mozilla Firefox plugin/nsScriptablePeer.cpp Uninitialized Po... |
73424 | SPICE Plugin for Mozilla Firefox usbrdrctl Log File Symlink Arbitrary File Ov... |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2013-07-12 | Name : The remote Oracle Linux host is missing a security update. File : oraclelinux_ELSA-2011-0426.nasl - Type : ACT_GATHER_INFO |
2013-01-24 | Name : The remote Red Hat host is missing a security update. File : redhat-RHSA-2011-0427.nasl - Type : ACT_GATHER_INFO |
2012-08-01 | Name : The remote Scientific Linux host is missing a security update. File : sl_20110407_spice_xpi_on_SL5_x.nasl - Type : ACT_GATHER_INFO |
2011-04-15 | Name : The remote CentOS host is missing a security update. File : centos_RHSA-2011-0427.nasl - Type : ACT_GATHER_INFO |
2011-04-08 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2011-0426.nasl - Type : ACT_GATHER_INFO |
Alert History
Date | Informations |
---|---|
2014-02-17 11:54:34 |
|