CVE-2020-14355
published 2020-10-07CVE-2020-14355: Multiple buffer overflow vulnerabilities were found in the QUIC image decoding process of the SPICE remote display system, before spice-0.14.2-1. Both the…
PriorityP338medium6.6CVSS 3.1
AVNACLPRHUINSCCLILAL
EPSS
2.66%
84.0th percentile
Multiple buffer overflow vulnerabilities were found in the QUIC image decoding process of the SPICE remote display system, before spice-0.14.2-1. Both the SPICE client (spice-gtk) and server are affected by these flaws. These flaws allow a malicious client or server to send specially crafted messages that, when processed by the QUIC image compression algorithm, result in a process crash or potential code execution.
Affected
26 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | spice | < spice 0.14.3-2 (bookworm) | spice 0.14.3-2 (bookworm) |
| debian | spice-gtk | < spice 0.14.3-2 (bookworm) | spice 0.14.3-2 (bookworm) |
| opensuse | leap | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux_aus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_tus | — | — |
| redhat | enterprise_linux_update_services_for_sap_solutions | — | — |
| redhat | openstack | — | — |
| spice-gtk_project | spice-gtk | >= 0 < 0.39-1 | 0.39-1 |
| spice-gtk_project | spice-gtk | >= 0 < 0.39-1 | 0.39-1 |
| spice-gtk_project | spice-gtk | >= 0 < 0.39-1 | 0.39-1 |
| spice-gtk_project | spice-gtk | >= 0 < 0.39-1 | 0.39-1 |
| spice_project | spice | < 0.14.2 | 0.14.2 |
| spice_project | spice | — | — |
| spice_project | spice | >= 0 < 0.14.3-2 | 0.14.3-2 |
| spice_project | spice | >= 0 < 0.14.3-2 | 0.14.3-2 |
| spice_project | spice | >= 0 < 0.14.3-2 | 0.14.3-2 |
CVSS provenance
nvdv3.16.6MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
osv6.6MEDIUM
vendor_debian6.6MEDIUM
vendor_redhat6.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Spice vulnerability
vendor_ubuntu·2020-10-07
CVE-2020-14355 Spice vulnerability
Title: Spice vulnerability
Summary: Spice could be made to crash or run programs if it received specially
crafted network traffic.
USN-4572-1 fixed a vulnerability in Spice. This update provides
the corresponding update for Ubuntu 14.04 ESM.
Original advisory details:
Frediano Ziglio discovered that Spice incorrectly handled QUIC image
decoding. A remote attacker could use this to cause Spice to crash,
resulting in a denial of service, or possibly execute arbitrary code.
Instructions: After a standard system update you need to restart qemu guests to make all
the necessary changes.
Red Hat
spice: multiple buffer overflow vulnerabilities in QUIC decoding code
vendor_redhat·2020-10-06·CVSS 6.6
CVE-2020-14355 [MEDIUM] CWE-120 spice: multiple buffer overflow vulnerabilities in QUIC decoding code
spice: multiple buffer overflow vulnerabilities in QUIC decoding code
Multiple buffer overflow vulnerabilities were found in the QUIC image decoding process of the SPICE remote display system, before spice-0.14.2-1. Both the SPICE client (spice-gtk) and server are affected by these flaws. These flaws allow a malicious client or server to send specially crafted messages that, when processed by the QUIC image compression algorithm, result in a process crash or potential code execution.
Multiple buffer overflow vulnerabilities were found in the QUIC image decoding process of the SPICE remote display system. Both the SPICE client (spice-gtk) and server are affected by these flaws. These flaws allow a malicious client or server to send specially crafted messages that, when processed by the QU
Ubuntu
Spice vulnerability
vendor_ubuntu·2020-10-06
CVE-2020-14355 Spice vulnerability
Title: Spice vulnerability
Summary: Spice could be made to crash or run programs if it received specially
crafted network traffic.
Frediano Ziglio discovered that Spice incorrectly handled QUIC image
decoding. A remote attacker could use this to cause Spice to crash,
resulting in a denial of service, or possibly execute arbitrary code.
Instructions: After a standard system update you need to restart qemu guests to make all
the necessary changes.
Debian
CVE-2020-14355: spice - Multiple buffer overflow vulnerabilities were found in the QUIC image decoding p...
vendor_debian·2020·CVSS 6.6
CVE-2020-14355 [MEDIUM] CVE-2020-14355: spice - Multiple buffer overflow vulnerabilities were found in the QUIC image decoding p...
Multiple buffer overflow vulnerabilities were found in the QUIC image decoding process of the SPICE remote display system, before spice-0.14.2-1. Both the SPICE client (spice-gtk) and server are affected by these flaws. These flaws allow a malicious client or server to send specially crafted messages that, when processed by the QUIC image compression algorithm, result in a process crash or potential code execution.
Scope: local
bookworm: resolved (fixed in 0.14.3-2)
bullseye: resolved (fixed in 0.14.3-2)
forky: resolved (fixed in 0.14.3-2)
sid: resolved (fixed in 0.14.3-2)
trixie: resolved (fixed in 0.14.3-2)
GHSA
GHSA-2457-jhx6-82v4: Multiple buffer overflow vulnerabilities were found in the QUIC image decoding process of the SPICE remote display system, before spice-0
ghsa_unreviewed·2022-05-24
CVE-2020-14355 [HIGH] CWE-120 GHSA-2457-jhx6-82v4: Multiple buffer overflow vulnerabilities were found in the QUIC image decoding process of the SPICE remote display system, before spice-0
Multiple buffer overflow vulnerabilities were found in the QUIC image decoding process of the SPICE remote display system, before spice-0.14.2-1. Both the SPICE client (spice-gtk) and server are affected by these flaws. These flaws allow a malicious client or server to send specially crafted messages that, when processed by the QUIC image compression algorithm, result in a process crash or potential code execution.
OSV
CVE-2020-14355: Multiple buffer overflow vulnerabilities were found in the QUIC image decoding process of the SPICE remote display system, before spice-0
osv·2020-10-07·CVSS 6.6
CVE-2020-14355 [MEDIUM] CVE-2020-14355: Multiple buffer overflow vulnerabilities were found in the QUIC image decoding process of the SPICE remote display system, before spice-0
Multiple buffer overflow vulnerabilities were found in the QUIC image decoding process of the SPICE remote display system, before spice-0.14.2-1. Both the SPICE client (spice-gtk) and server are affected by these flaws. These flaws allow a malicious client or server to send specially crafted messages that, when processed by the QUIC image compression algorithm, result in a process crash or potential code execution.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-14355 spice: multiple buffer overflow vulnerabilities in QUIC decoding code [fedora-all]
bugzilla·2020-10-06·CVSS 6.6
CVE-2020-14355 [MEDIUM] CVE-2020-14355 spice: multiple buffer overflow vulnerabilities in QUIC decoding code [fedora-all]
CVE-2020-14355 spice: multiple buffer overflow vulnerabilities in QUIC decoding code [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multipl
Bugzilla
CVE-2020-14355 spice-gtk: spice: multiple buffer overflow vulnerabilities in QUIC decoding code [fedora-all]
bugzilla·2020-10-06·CVSS 6.6
CVE-2020-14355 [MEDIUM] CVE-2020-14355 spice-gtk: spice: multiple buffer overflow vulnerabilities in QUIC decoding code [fedora-all]
CVE-2020-14355 spice-gtk: spice: multiple buffer overflow vulnerabilities in QUIC decoding code [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affe
Bugzilla
CVE-2020-14355 spice: multiple buffer overflow vulnerabilities in QUIC decoding code
bugzilla·2020-08-12·CVSS 6.6
CVE-2020-14355 [MEDIUM] CVE-2020-14355 spice: multiple buffer overflow vulnerabilities in QUIC decoding code
CVE-2020-14355 spice: multiple buffer overflow vulnerabilities in QUIC decoding code
Multiple buffer overflow vulnerabilities were found in the QUIC image decoding process of the SPICE remote display system. More specifically, these flaws reside in the spice-common shared code between the client and server of SPICE. In other words, both the client (spice-gtk) and server are affected by these flaws. A malicious client or server could send specially crafted messages which would result in a process crash or potential code execution.
Upstream commits:
* https://gitlab.freedesktop.org/spice/spice-common/-/commit/762e0aba
* https://gitlab.freedesktop.org/spice/spice-common/-/commit/404d7478
* https://gitlab.freedesktop.org/spice/spice-common/-/commit/ef1b6ff7
* https://gitlab.freedesktop.org/s
Bugzilla
CVE-2018-14355 mutt: IMAP header caching path traversal vulnerability
bugzilla·2018-07-17·CVSS 5.3
CVE-2018-14355 [MEDIUM] CVE-2018-14355 mutt: IMAP header caching path traversal vulnerability
CVE-2018-14355 mutt: IMAP header caching path traversal vulnerability
A flaw was found in mutt before 1.10.1. There is a path traversal flaw in IMAP header caching.
References:
http://www.mutt.org/news.html
https://gitlab.com/muttmua/mutt/blob/master/ChangeLog
Discussion:
Created attachment 1459537
upstream patch
---
Created mutt tracking bugs for this issue:
Affects: fedora-all [bug 1602082]
---
Upstream Patch:
https://gitlab.com/muttmua/mutt/commit/31eef6c766f47df8281942d19f76e35f475c781d
---
Setting rhel-6 as wontfix and closing tracker. Our policy specifies that we may not fix moderate flaws for rhel-6.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:1126 https://access.redhat.com/errata/RHSA-2020:1126
---
This bug
http://lists.opensuse.org/opensuse-security-announce/2020-11/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-11/msg00001.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=1868435https://lists.debian.org/debian-lts-announce/2020/11/msg00001.htmlhttps://lists.debian.org/debian-lts-announce/2020/11/msg00002.htmlhttps://usn.ubuntu.com/4572-1/https://usn.ubuntu.com/4572-2/https://www.debian.org/security/2020/dsa-4771https://www.openwall.com/lists/oss-security/2020/10/06/10http://lists.opensuse.org/opensuse-security-announce/2020-11/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-11/msg00001.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=1868435https://lists.debian.org/debian-lts-announce/2020/11/msg00001.htmlhttps://lists.debian.org/debian-lts-announce/2020/11/msg00002.htmlhttps://usn.ubuntu.com/4572-1/https://usn.ubuntu.com/4572-2/https://www.debian.org/security/2020/dsa-4771https://www.openwall.com/lists/oss-security/2020/10/06/10
2020-10-07
Published