USN-3355-1: Spice vulnerability Ubuntu Security Notice USN-3355-1 19th July, 2017 spice vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 17.04 Ubuntu 16.04 LTS Ubuntu 14.04 LTS Summary Spice could be made to crash or run programs if it received specially crafted network traffic. Software description spice – SPICE protocol client and server library Details Frediano Ziglio discovered that Spice incorrectly handled certain invalidmonitor configurations. A remote attacker could use this issue to causeSpice to crash, resulting in a denial of service, or possibly executearbitrary code. Update instructions The problem can be corrected by updating your system to the following package version: Ubuntu 17.04: libspice-server1 0.12.8-2ubuntu1.1 Ubuntu 16.04 LTS: libspice-server1 0.12.6-4ubuntu0.3 Ubuntu 14.04 LTS: libspice-server1 0.12.4-0nocelt2ubuntu1.5 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. After a standard system update you need to restart qemu guests [ more… ]