Format: 1.8 Date: Wed, 22 Jun 2016 03:11:54 +0000 Source: spice Binary: spice-client libspice-server1 libspice-server-dev Architecture: source Version: 0.12.4-0nocelt2ubuntu1.3~cloud0 Distribution: precise Urgency: medium Maintainer: Ubuntu Developers Changed-By: Openstack Ubuntu Testing Bot Description: libspice-server-dev - Header files and development documentation for spice-server libspice-server1 - Implements the server side of the SPICE protocol spice-client - Implements the client side of the SPICE protocol Changes: spice (0.12.4-0nocelt2ubuntu1.3~cloud0) precise-icehouse; urgency=medium . * New update for the Ubuntu Cloud Archive. . spice (0.12.4-0nocelt2ubuntu1.3) trusty-security; urgency=medium . * SECURITY UPDATE: denial of service and possible code execution via memory allocation flaw in smartcard interaction - debian/patches/CVE-2016-0749/*.patch: add a ref to item and allocate msg with the expected size in server/smartcard.c. - CVE-2016-0749 * SECURITY UPDATE: host memory access from guest with invalid primary surface parameters - debian/patches/CVE-2016-2150/*.patch: create a function to validate surface parameters in server/red_parse_qxl.*, improve primary surface parameter checks in server/red_worker.c. - CVE-2016-2150 * Added two extra commits to previous security update: - 0001-worker-validate-correctly-surfaces.patch - 0002-worker-avoid-double-free-or-double-create-of-surface.patch Checksums-Sha1: 2e5874f9a10a4f99a3ad07759d54c883ea24f64a 2362 spice_0.12.4-0nocelt2ubuntu1.3~cloud0.dsc 5825cfcf8a786697e45a43aaf372f23b5c441336 1718655 spice_0.12.4.orig.tar.bz2 c97503554d9c84d8b3b984b15da405cf1d145459 38753 spice_0.12.4-0nocelt2ubuntu1.3~cloud0.debian.tar.gz Checksums-Sha256: 91263c51ee6fcc154de7fc64f7fa73d2e1d056008fbc717d27b5eba4f1657cb6 2362 spice_0.12.4-0nocelt2ubuntu1.3~cloud0.dsc cf063e7df42e331a835529d2f613d8a01f8cb2963e8edaadf73a8d65c46fb387 1718655 spice_0.12.4.orig.tar.bz2 5c7caf796a4ed24d4c41cf18b1fe2ec414a4e53df8fa32a771801544fb0f7715 38753 spice_0.12.4-0nocelt2ubuntu1.3~cloud0.debian.tar.gz Files: 67036aee6353f8d44d5240ec26b615bf 2362 misc optional spice_0.12.4-0nocelt2ubuntu1.3~cloud0.dsc 325b1c42ce24e75de45a75876b73a8bd 1718655 misc optional spice_0.12.4.orig.tar.bz2 83f31b830392d0aa2dd146b461d5b57d 38753 misc optional spice_0.12.4-0nocelt2ubuntu1.3~cloud0.debian.tar.gz Original-Maintainer: Liang Guo