First published: Fri Feb 26 2010(Updated: )
libspice, as used in QEMU-KVM in Red Hat Enterprise Virtualization Hypervisor (aka RHEV-H or rhev-hypervisor) before 5.5-2.2 and possibly other products, allows guest OS users to read from or write to arbitrary QEMU memory by modifying the address that is used by Cairo for memory mappings.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Redhat Enterprise Virtualization Hypervisor | <=5.4-2.1 | |
redhat/kvm | <0:83-164.el5 | 0:83-164.el5 |
redhat/rhev-hypervisor | <0:5.5-2.2.4.2.el5 | 0:5.5-2.2.4.2.el5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.