A flaw was found in the SPICE file transfer protocol. File data from the host system can end up in full or in parts in the client connection of an illegitimate local user in the VM system. Active file transfers from other users could also be interrupted, resulting in a denial of service. The highest threat from this vulnerability is to data confidentiality as well as system availability. This flaw affects spice-vdagent versions 0.20 and prior.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: redhat
Published: 2020-11-26T01:18:45
Updated: 2024-08-04T15:40:36.225Z
Reserved: 2020-09-16T00:00:00
Link: CVE-2020-25651
Vulnrichment
No data.
NVD
Status : Modified
Published: 2020-11-26T02:15:11.743
Modified: 2024-11-21T05:18:21.133
Link: CVE-2020-25651
Redhat