Security Advisory Important: rhevm-spice-client security update

Advisory: RHSA-2014:0416-1
Type: Security Advisory
Severity: Important
Issued on: 2014-04-17
Last updated on: 2014-04-17
Affected Products: Red Hat Enterprise Virtualization 3.3
CVEs ( CVE-2012-4929


Updated rhevm-spice-client packages that fix multiple security issues are
now available for Red Hat Enterprise Virtualization Manager 3.

The Red Hat Security Response Team has rated this update as having
Important security impact. Common Vulnerability Scoring System (CVSS) base
scores, which give detailed severity ratings, are available for each
vulnerability from the CVE links in the References section.

Red Hat Enterprise Virtualization Manager provides access to virtual
machines using SPICE. These SPICE client packages provide the SPICE client
and usbclerk service for both Windows 32-bit operating systems and Windows
64-bit operating systems.

The rhevm-spice-client package includes the mingw-virt-viewer Windows SPICE
client. OpenSSL, a general purpose cryptography library with a TLS
implementation, is bundled with mingw-virt-viewer. The mingw-virt-viewer
package has been updated to correct the following issues:

An information disclosure flaw was found in the way OpenSSL handled TLS and
DTLS Heartbeat Extension packets. A malicious TLS or DTLS client or server
could send a specially crafted TLS or DTLS Heartbeat packet to disclose a
limited portion of memory per request from a connected client or server.
Note that the disclosed portions of memory could potentially include
sensitive information such as private keys. (CVE-2014-0160)

It was discovered that OpenSSL leaked timing information when decrypting
TLS/SSL and DTLS protocol encrypted records when CBC-mode cipher suites
were used. A remote attacker could possibly use this flaw to retrieve plain
text from the encrypted packets by using a TLS/SSL or DTLS server as a
padding oracle. (CVE-2013-0169)

A NULL pointer dereference flaw was found in the way OpenSSL handled
TLS/SSL protocol handshake packets. A specially crafted handshake packet
could cause a TLS/SSL client using OpenSSL to crash. (CVE-2013-4353)

It was discovered that the TLS/SSL protocol could leak information about
plain text when optional compression was used. An attacker able to control
part of the plain text sent over an encrypted TLS/SSL connection could
possibly use this flaw to recover other portions of the plain text.

Red Hat would like to thank the OpenSSL project for reporting
CVE-2014-0160. Upstream acknowledges Neel Mehta of Google Security as the
original reporter.

The updated mingw-virt-viewer Windows SPICE client further includes OpenSSL
security fixes that have no security impact on mingw-virt-viewer itself.
The security fixes included in this update address the following CVE

CVE-2013-6449, CVE-2013-6450, CVE-2012-2686, and CVE-2013-0166

All Red Hat Enterprise Virtualization Manager users are advised to upgrade
to these updated packages, which address these issues.


Before applying this update, make sure all previously released errata
relevant to your system have been applied.

This update is available via the Red Hat Network. Details on how to
use the Red Hat Network to apply this update are available at

Updated packages

Red Hat Enterprise Virtualization 3.3

File outdated by:  RHBA-2014:0829
    MD5: 60cd080f360601e46e74aca4dee188d9
SHA-256: 8c9eec8287ce914c9615389206bd3422e0ac1b0a718d28c4c723577ee403b892
File outdated by:  RHBA-2014:0829
    MD5: 68964fefff80b48bb45ab62722eed1f9
SHA-256: f958b9a343cf4ada7430f307fd9e2ff91e625cb39fe4eeb98c525acb21ec8689
File outdated by:  RHBA-2014:0829
    MD5: 1c6076f7c3707df064f259ee5dccd694
SHA-256: a500de9949e4f903211e8fdf99a58be498aa8095f0b4f6dd46d19cacf2023c32
File outdated by:  RHBA-2014:0829
    MD5: 43b5929201d077a2dba37f9c3c1061a8
SHA-256: dea6376e50f2f91f9375cb659e70e24220201d5a4ab219f7053042a9e62ab266
File outdated by:  RHBA-2014:0829
    MD5: ae8e7a48c7e2327b837bf8561dfb88d1
SHA-256: 8ed964e4a4c765e1cc8271877d4716b28d17a9c47bdcde430876b05ef8bace33
(The unlinked packages above are only available from the Red Hat Network)

Bugs fixed (see bugzilla for more information)

1049058 - CVE-2013-4353 openssl: client NULL dereference crash on malformed handshake packets
1084875 - CVE-2014-0160 openssl: information disclosure in handling of TLS heartbeat extension packets
857051 - CVE-2012-4929 SSL/TLS CRIME attack against HTTPS
907589 - CVE-2013-0169 SSL/TLS: CBC padding timing attack (lucky-13)


These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from:

The Red Hat security contact is More contact details at