Package        : spice
Version        : 0.12.5-1+deb8u7
CVE ID         : CVE-2019-3813
Debian Bug     : 920762

Christophe Fergeau discovered an out-of-bounds read vulnerability in
spice, a SPICE protocol client and server library, which might result in
denial of service (spice server crash), or possibly, execution of
arbitrary code.

For Debian 8 "Jessie", this problem has been fixed in version
0.12.5-1+deb8u7.

We recommend that you upgrade your spice packages.

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS

Debian LTS: DLA-1649-1: spice security update

January 30, 2019
Christophe Fergeau discovered an out-of-bounds read vulnerability in spice, a SPICE protocol client and server library, which might result in denial of service (spice server crash)...

Summary

We recommend that you upgrade your spice packages.

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS


Severity
Package : spice
Version : 0.12.5-1+deb8u7
CVE ID : CVE-2019-3813
Debian Bug : 920762

Related News