Description
Multiple buffer overflow vulnerabilities were found in the QUIC image decoding process of the SPICE remote display system, before spice-0.14.2-1. Both the SPICE client (spice-gtk) and server are affected by these flaws. These flaws allow a malicious client or server to send specially crafted messages that, when processed by the QUIC image compression algorithm, result in a process crash or potential code execution.
Published: 2020-10-07
Score: 6.6 Medium
EPSS: 1.1% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-2427-1 spice security update
Debian DLA Debian DLA DLA-2428-1 spice-gtk security update
Debian DSA Debian DSA DSA-4771-1 spice security update
EUVD EUVD EUVD-2020-6499 Multiple buffer overflow vulnerabilities were found in the QUIC image decoding process of the SPICE remote display system, before spice-0.14.2-1. Both the SPICE client (spice-gtk) and server are affected by these flaws. These flaws allow a malicious client or server to send specially crafted messages that, when processed by the QUIC image compression algorithm, result in a process crash or potential code execution.
Ubuntu USN Ubuntu USN USN-4572-1 Spice vulnerability
Ubuntu USN Ubuntu USN USN-4572-2 Spice vulnerability
History

No history.

Subscriptions

Canonical Ubuntu Linux
Debian Debian Linux
Opensuse Leap
Redhat Enterprise Linux Enterprise Linux Aus Enterprise Linux Eus Enterprise Linux Tus Enterprise Linux Update Services For Sap Solutions Openstack Rhel E4s Rhel Eus
Spice Project Spice
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2024-08-04T12:39:36.601Z

Reserved: 2020-06-17T00:00:00.000Z

Link: CVE-2020-14355

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-10-07T15:15:12.397

Modified: 2024-11-21T05:03:04.860

Link: CVE-2020-14355

cve-icon Redhat

Severity : Important

Publid Date: 2020-10-06T12:00:00Z

Links: CVE-2020-14355 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses