File _patchinfo of Package patchinfo.7965

<patchinfo incident="7965">
  <issue id="1085415" tracker="bnc">VUL-0: CVE-2017-12194: spice-gtk: A flaw was found in the way spice-client processed certain messages sent fromthe server. An attacker, having control of malicious spice-server, could usethis flaw to crash the client or execute arbitrary</issue>
  <issue id="2017-12194" tracker="cve" />
  <category>security</category>
  <rating>moderate</rating>
  <packager>cbosdonnat</packager>
  <description>This update for spice-gtk fixes the following issues:

- CVE-2017-12194: A flaw was found in the way spice-client processed certain messages sent from the server. An attacker, having control of malicious spice-server, could use this flaw to crash the client or execute arbitrary code with permissions of the user running the client. spice-gtk versions through 0.34 are believed to be vulnerable. (bsc#1085415)

This update was imported from the SUSE:SLE-12-SP3:Update update project.</description>
  <summary>Security update for spice-gtk</summary>
</patchinfo>
openSUSE Build Service is sponsored by