Multiple buffer overflow vulnerabilities were found in the QUIC image decoding process of the SPICE remote display system, before spice-0.14.2-1. Both the SPICE client (spice-gtk) and server are affected by these flaws. These flaws allow a malicious client or server to send specially crafted messages that, when processed by the QUIC image compression algorithm, result in a process crash or potential code execution.

Project Subscriptions

Vendors Products
Canonical Subscribe
Ubuntu Linux Subscribe
Debian Linux Subscribe
Opensuse Subscribe
Enterprise Linux Subscribe
Enterprise Linux Aus Subscribe
Enterprise Linux Eus Subscribe
Enterprise Linux Tus Subscribe
Enterprise Linux Update Services For Sap Solutions Subscribe
Openstack Subscribe
Rhel E4s Subscribe
Rhel Eus Subscribe
Spice Project Subscribe
Advisories
Source ID Title
Debian DLA Debian DLA DLA-2427-1 spice security update
Debian DLA Debian DLA DLA-2428-1 spice-gtk security update
Debian DSA Debian DSA DSA-4771-1 spice security update
EUVD EUVD EUVD-2020-6499 Multiple buffer overflow vulnerabilities were found in the QUIC image decoding process of the SPICE remote display system, before spice-0.14.2-1. Both the SPICE client (spice-gtk) and server are affected by these flaws. These flaws allow a malicious client or server to send specially crafted messages that, when processed by the QUIC image compression algorithm, result in a process crash or potential code execution.
Ubuntu USN Ubuntu USN USN-4572-1 Spice vulnerability
Ubuntu USN Ubuntu USN USN-4572-2 Spice vulnerability
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2024-08-04T12:39:36.601Z

Reserved: 2020-06-17T00:00:00

Link: CVE-2020-14355

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-10-07T15:15:12.397

Modified: 2024-11-21T05:03:04.860

Link: CVE-2020-14355

cve-icon Redhat

Severity : Important

Publid Date: 2020-10-06T12:00:00Z

Links: CVE-2020-14355 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses