Description
Multiple buffer overflow vulnerabilities were found in the QUIC image decoding process of the SPICE remote display system, before spice-0.14.2-1. Both the SPICE client (spice-gtk) and server are affected by these flaws. These flaws allow a malicious client or server to send specially crafted messages that, when processed by the QUIC image compression algorithm, result in a process crash or potential code execution.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-2427-1 | spice security update |
Debian DLA |
DLA-2428-1 | spice-gtk security update |
Debian DSA |
DSA-4771-1 | spice security update |
EUVD |
EUVD-2020-6499 | Multiple buffer overflow vulnerabilities were found in the QUIC image decoding process of the SPICE remote display system, before spice-0.14.2-1. Both the SPICE client (spice-gtk) and server are affected by these flaws. These flaws allow a malicious client or server to send specially crafted messages that, when processed by the QUIC image compression algorithm, result in a process crash or potential code execution. |
Ubuntu USN |
USN-4572-1 | Spice vulnerability |
Ubuntu USN |
USN-4572-2 | Spice vulnerability |
References
History
No history.
Subscriptions
Canonical
Subscribe
Ubuntu Linux
Subscribe
Debian
Subscribe
Debian Linux
Subscribe
Opensuse
Subscribe
Leap
Subscribe
Redhat
Subscribe
Enterprise Linux
Subscribe
Enterprise Linux Aus
Subscribe
Enterprise Linux Eus
Subscribe
Enterprise Linux Tus
Subscribe
Enterprise Linux Update Services For Sap Solutions
Subscribe
Openstack
Subscribe
Rhel E4s
Subscribe
Rhel Eus
Subscribe
Spice Project
Subscribe
Spice
Subscribe
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-04T12:39:36.601Z
Reserved: 2020-06-17T00:00:00.000Z
Link: CVE-2020-14355
No data.
Status : Modified
Published: 2020-10-07T15:15:12.397
Modified: 2024-11-21T05:03:04.860
Link: CVE-2020-14355
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
Debian DSA
EUVD
Ubuntu USN