Vulnerability   
Search   
    Search 211766 CVE descriptions
and 97459 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.67898
Category:Red Hat Local Security Checks
Title:RedHat Security Advisory RHSA-2010:0651
Summary:NOSUMMARY
Description:Description:
The remote host is missing updates announced in
advisory RHSA-2010:0651.

The Simple Protocol for Independent Computing Environments (SPICE) is a
remote display protocol used in Red Hat Enterprise Linux for viewing
virtualized guests running on the Kernel-based Virtual Machine (KVM)
hypervisor, or on Red Hat Enterprise Virtualization Hypervisor.

The spice-xpi package provides a plug-in that allows the SPICE client to
run from within Mozilla Firefox.

A race condition was found in the way the SPICE Firefox plug-in and the
SPICE client communicated. A local attacker could use this flaw to trick
the plug-in and the SPICE client into communicating over an
attacker-controlled socket, possibly gaining access to authentication
details, or resulting in a man-in-the-middle attack on the SPICE
connection. (CVE-2010-2792)

It was found that the SPICE Firefox plug-in used a predictable name for its
log file. A local attacker could use this flaw to conduct a symbolic link
attack, allowing them to overwrite arbitrary files accessible to the user
running Firefox. (CVE-2010-2794)

Solution:
Users of spice-xpi should upgrade to this updated package, which contains
backported patches to correct these issues. After installing the update,
Firefox must be restarted for the changes to take effect.

Please note that this update is available via
Red Hat Network. To use Red Hat Network, launch the Red
Hat Update Agent with the following command: up2date

http://rhn.redhat.com/errata/RHSA-2010-0651.html
http://www.redhat.com/security/updates/classification/#moderate

Risk factor : Medium

CVSS Score:
3.3

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2010-2792
BugTraq ID: 42711
http://www.securityfocus.com/bid/42711
http://osvdb.org/67619
http://www.redhat.com/support/errata/RHSA-2010-0632.html
http://www.redhat.com/support/errata/RHSA-2010-0651.html
http://secunia.com/advisories/41120
http://www.vupen.com/english/advisories/2010/2181
Common Vulnerability Exposure (CVE) ID: CVE-2010-2794
http://osvdb.org/67620
CopyrightCopyright (c) 2010 E-Soft Inc. http://www.securityspace.com

This is only one of 97459 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2021 E-Soft Inc. All rights reserved.