cbcvebase.
CVE-2020-14355
published 2020-10-07

CVE-2020-14355: Multiple buffer overflow vulnerabilities were found in the QUIC image decoding process of the SPICE remote display system, before spice-0.14.2-1. Both the…

medium6.6CVSS 3.1
AVNACLPRHUINSCCLILAL
Multiple buffer overflow vulnerabilities were found in the QUIC image decoding process of the SPICE remote display system, before spice-0.14.2-1. Both the SPICE client (spice-gtk) and server are affected by these flaws. These flaws allow a malicious client or server to send specially crafted messages that, when processed by the QUIC image compression algorithm, result in a process crash or potential code execution.

Affected

26 ranges· showing 25
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debianspice< spice 0.14.3-2 (bookworm)spice 0.14.3-2 (bookworm)
debianspice-gtk< spice 0.14.3-2 (bookworm)spice 0.14.3-2 (bookworm)
opensuseleap
redhatenterprise_linux
redhatenterprise_linux
redhatenterprise_linux
redhatenterprise_linux_aus
redhatenterprise_linux_eus
redhatenterprise_linux_tus
redhatenterprise_linux_update_services_for_sap_solutions
redhatopenstack
spice-gtk_projectspice-gtk>= 0 < 0.39-10.39-1
spice-gtk_projectspice-gtk>= 0 < 0.39-10.39-1
spice-gtk_projectspice-gtk>= 0 < 0.39-10.39-1
spice-gtk_projectspice-gtk>= 0 < 0.39-10.39-1
spice_projectspice< 0.14.20.14.2
spice_projectspice
spice_projectspice>= 0 < 0.14.3-20.14.3-2
spice_projectspice>= 0 < 0.14.3-20.14.3-2
spice_projectspice>= 0 < 0.14.3-20.14.3-2

CVSS provenance

nvdv3.16.6MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L
osv6.6MEDIUM