Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-20201

Опубликовано: 28 мая 2021
Источник: debian
EPSS Низкий

Описание

A flaw was found in spice in versions before 0.14.92. A DoS tool might make it easier for remote attackers to cause a denial of service (CPU consumption) by performing many renegotiations within a single connection.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
spicefixed0.14.3-2.1package
spiceno-dsabusterpackage
spiceno-dsastretchpackage

Примечания

  • https://gitlab.freedesktop.org/spice/spice/-/issues/49

  • https://gitlab.freedesktop.org/spice/spice/-/commit/ca5bbc5692e052159bce1a75f55dc60b36078749

  • https://gitlab.freedesktop.org/spice/spice/-/commit/95a0cfac8a1c8eff50f05e65df945da3bb501fc9

  • https://blog.qualys.com/product-tech/2011/10/31/tls-renegotiation-and-denial-of-service-attacks

EPSS

Процентиль: 39%
0.00167
Низкий

Связанные уязвимости

CVSS3: 5.3
ubuntu
около 4 лет назад

A flaw was found in spice in versions before 0.14.92. A DoS tool might make it easier for remote attackers to cause a denial of service (CPU consumption) by performing many renegotiations within a single connection.

CVSS3: 5.3
redhat
больше 4 лет назад

A flaw was found in spice in versions before 0.14.92. A DoS tool might make it easier for remote attackers to cause a denial of service (CPU consumption) by performing many renegotiations within a single connection.

CVSS3: 5.3
nvd
около 4 лет назад

A flaw was found in spice in versions before 0.14.92. A DoS tool might make it easier for remote attackers to cause a denial of service (CPU consumption) by performing many renegotiations within a single connection.

suse-cvrf
около 4 лет назад

Security update for spice

suse-cvrf
почти 3 года назад

Security update for spice

EPSS

Процентиль: 39%
0.00167
Низкий