Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-14355

Опубликовано: 06 окт. 2020
Источник: redhat
CVSS3: 6.6
EPSS Низкий

Описание

Multiple buffer overflow vulnerabilities were found in the QUIC image decoding process of the SPICE remote display system, before spice-0.14.2-1. Both the SPICE client (spice-gtk) and server are affected by these flaws. These flaws allow a malicious client or server to send specially crafted messages that, when processed by the QUIC image compression algorithm, result in a process crash or potential code execution.

Multiple buffer overflow vulnerabilities were found in the QUIC image decoding process of the SPICE remote display system. Both the SPICE client (spice-gtk) and server are affected by these flaws. These flaws allow a malicious client or server to send specially crafted messages that, when processed by the QUIC image compression algorithm, result in a process crash or potential code execution.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6spice-clientOut of support scope
Red Hat Enterprise Linux 6spice-gtkOut of support scope
Red Hat Enterprise Linux 6spice-serverOut of support scope
Red Hat Enterprise Linux 9spiceNot affected
Red Hat Enterprise Linux 7spiceFixedRHSA-2020:418706.10.2020
Red Hat Enterprise Linux 7spice-gtkFixedRHSA-2020:418706.10.2020
Red Hat Enterprise Linux 8spiceFixedRHSA-2020:418606.10.2020
Red Hat Enterprise Linux 8spice-gtkFixedRHSA-2020:418606.10.2020
Red Hat Enterprise Linux 8.0 Update Services for SAP SolutionsspiceFixedRHSA-2020:418406.10.2020
Red Hat Enterprise Linux 8.0 Update Services for SAP Solutionsspice-gtkFixedRHSA-2020:418406.10.2020

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-120
https://bugzilla.redhat.com/show_bug.cgi?id=1868435spice: multiple buffer overflow vulnerabilities in QUIC decoding code

EPSS

Процентиль: 78%
0.01111
Низкий

6.6 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.6
ubuntu
больше 5 лет назад

Multiple buffer overflow vulnerabilities were found in the QUIC image decoding process of the SPICE remote display system, before spice-0.14.2-1. Both the SPICE client (spice-gtk) and server are affected by these flaws. These flaws allow a malicious client or server to send specially crafted messages that, when processed by the QUIC image compression algorithm, result in a process crash or potential code execution.

CVSS3: 6.6
nvd
больше 5 лет назад

Multiple buffer overflow vulnerabilities were found in the QUIC image decoding process of the SPICE remote display system, before spice-0.14.2-1. Both the SPICE client (spice-gtk) and server are affected by these flaws. These flaws allow a malicious client or server to send specially crafted messages that, when processed by the QUIC image compression algorithm, result in a process crash or potential code execution.

CVSS3: 6.6
debian
больше 5 лет назад

Multiple buffer overflow vulnerabilities were found in the QUIC image ...

suse-cvrf
больше 5 лет назад

Security update for spice-gtk

suse-cvrf
больше 5 лет назад

Security update for spice

EPSS

Процентиль: 78%
0.01111
Низкий

6.6 Medium

CVSS3