RHSA-2014:0416: Important: rhevm-spice-client security update
Red Hat Enterprise Virtualization Manager provides access to virtualmachines using SPICE. These SPICE client packages provide the SPICE clientand usbclerk service for both Windows 32-bit operating systems and Windows64-bit operating systems.The rhevm-spice-client package includes the mingw-virt-viewer Windows SPICEclient. OpenSSL, a general purpose cryptography library with a TLSimplementation, is bundled with mingw-virt-viewer. The mingw-virt-viewerpackage has been updated to correct the following issues:An information disclosure flaw was found in the way OpenSSL handled TLS andDTLS Heartbeat Extension packets. A malicious TLS or DTLS client or servercould send a specially crafted TLS or DTLS Heartbeat packet to disclose alimited portion of memory per request from a connected client or server.Note that the disclosed portions of memory could potentially includesensitive information such as private keys. (CVE-2014-0160)It was discovered that OpenSSL leaked timing information when decryptingTLS/SSL and DTLS protocol encrypted records when CBC-mode cipher suiteswere used. A remote attacker could possibly use this flaw to retrieve plaintext from the encrypted packets by using a TLS/SSL or DTLS server as apadding oracle. (CVE-2013-0169)A NULL pointer dereference flaw was found in the way OpenSSL handledTLS/SSL protocol handshake packets. A specially crafted handshake packetcould cause a TLS/SSL client using OpenSSL to crash. (CVE-2013-4353)It was discovered that the TLS/SSL protocol could leak information aboutplain text when optional compression was used. An attacker able to controlpart of the plain text sent over an encrypted TLS/SSL connection couldpossibly use this flaw to recover other portions of the plain text.(CVE-2012-4929)Red Hat would like to thank the OpenSSL project for reportingCVE-2014-0160. Upstream acknowledges Neel Mehta of Google Security as theoriginal reporter.The updated mingw-virt-viewer Windows SPICE client further includes OpenSSLsecurity fixes that have no security impact on mingw-virt-viewer itself.The security fixes included in this update address the following CVEnumbers:CVE-2013-6449, CVE-2013-6450, CVE-2012-2686, and CVE-2013-0166All Red Hat Enterprise Virtualization Manager users are advised to upgradeto these updated packages, which address these issues.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2014:0416?
The severity of RHSA-2014:0416 is rated as important.
How do I fix RHSA-2014:0416?
To fix RHSA-2014:0416, update the rhevm-spice-client package to version 3.3-12.el6_5.
What packages are affected in RHSA-2014:0416?
The affected packages in RHSA-2014:0416 include rhevm-spice-client, rhevm-spice-client-x64-cab, rhevm-spice-client-x64-msi, rhevm-spice-client-x86-cab, and rhevm-spice-client-x86-msi.
What does RHSA-2014:0416 address?
RHSA-2014:0416 addresses vulnerabilities in the SPICE client packages used by Red Hat Enterprise Virtualization Manager.
Is RHSA-2014:0416 applicable to both 32-bit and 64-bit systems?
Yes, RHSA-2014:0416 is applicable to both Windows 32-bit and Windows 64-bit operating systems.