Multiple buffer overflow vulnerabilities were found in the QUIC image decoding process of the SPICE remote display system, before spice-0.14.2-1. Both the SPICE client (spice-gtk) and server are affected by these flaws. These flaws allow a malicious client or server to send specially crafted messages that, when processed by the QUIC image compression algorithm, result in a process crash or potential code execution.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2020-10-07T14:41:18

Updated: 2024-08-04T12:39:36.601Z

Reserved: 2020-06-17T00:00:00

Link: CVE-2020-14355

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2020-10-07T15:15:12.397

Modified: 2023-11-09T20:11:15.350

Link: CVE-2020-14355

cve-icon Redhat

Severity : Important

Publid Date: 2020-10-06T12:00:00Z

Links: CVE-2020-14355 - Bugzilla