CVE-2015-3247: Race Condition
Published Sep 8, 2015
·Updated
Race condition in the workerupdatemonitorsconfig function in SPICE 0.12.4 allows a remote authenticated guest user to cause a denial of service (heap-based memory corruption and QEMU-KVM crash) or possibly execute arbitrary code on the host via unspecified vectors.
Affected Software
11 affected components
Spice Project Spice=0.12.4
redhat Enterprise Linux=6.0
redhat Enterprise Linux=7.0
redhat Enterprise Linux Desktop=6.0
redhat Enterprise Linux Desktop=7.0
redhat Enterprise Linux Hpc Node=6
redhat Enterprise Linux Hpc Node=7.0
redhat Enterprise Linux Server=6.0
redhat Enterprise Linux Server=7.0
redhat Enterprise Linux Workstation=6.0
redhat Enterprise Linux Workstation=7.0
Event History
Sep 8, 2015
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-3247?
CVE-2015-3247 has a severity rating that can lead to denial of service and potential arbitrary code execution.
2
How do I fix CVE-2015-3247?
To fix CVE-2015-3247, it is recommended to update to a non-vulnerable version of SPICE.
3
What causes the vulnerabilities in CVE-2015-3247?
CVE-2015-3247 is caused by a race condition in the worker_update_monitors_config function in SPICE.
4
Who is affected by CVE-2015-3247?
Remote authenticated guest users on SPICE version 0.12.4 may exploit CVE-2015-3247.
5
What kind of attacks can be executed using CVE-2015-3247?
CVE-2015-3247 can be exploited to cause heap-based memory corruption and crashes in QEMU-KVM.