PT-2020-6186 · Red Hat+5 · Spice+7

Frediano Ziglio

·

Published

2019-06-03

·

Updated

2024-06-15

·

CVE-2020-14355

CVSS v3.1

6.6

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions SPICE versions prior to 0.14.2-1 spice-gtk versions prior to 0.14.2-1
Description The issue is related to buffer overflow vulnerabilities in the QUIC image decoding process of the SPICE remote display system. These vulnerabilities can be exploited by a malicious client or server sending specially crafted messages, which can result in a process crash or potential code execution when processed by the QUIC image compression algorithm. This could allow an attacker to access confidential data, compromise its integrity, and cause a denial of service.
Recommendations For SPICE versions prior to 0.14.2-1, update to version 0.14.2-1 or later to resolve the issue. For spice-gtk versions prior to 0.14.2-1, update to version 0.14.2-1 or later to resolve the issue. As a temporary workaround, consider restricting access to the QUIC image decoding process until a patch is available.

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2019-1972
ALT-PU-2019-1989
ALT-PU-2021-1700
ALT-PU-2021-1879
ALT-PU-2021-1963
BDU:2021-03500
CESA-2020_4186
CESA-2020_4187
CVE-2020-14355
DLA-2427-1
DLA-2428-1
DSA-4771-1
MGASA-2020-0408
OESA-2021-1082
OPENSUSE-SU-2020:1802-1
OPENSUSE-SU-2020:1803-1
OPENSUSE-SU-2020_1802-1
OPENSUSE-SU-2020_1803-1
OPENSUSE-SU-2024:11397-1
OPENSUSE-SU-2024:11398-1
RHSA-2020:4184
RHSA-2020:4185
RHSA-2020:4186
RHSA-2020:4187
RHSA-2020_4186
RHSA-2020_4187
SUSE-SU-2020:3070-1
SUSE-SU-2020:3071-1
SUSE-SU-2020:3084-1
SUSE-SU-2020:3085-1
SUSE-SU-2020_3070-1
SUSE-SU-2020_3071-1
SUSE-SU-2020_3084-1
SUSE-SU-2020_3085-1
SUSE-SU-2021:14744-1
SUSE-SU-2021:1901-1
SUSE-SU-2021:1902-1
SUSE-SU-2021:1905-1
SUSE-SU-2021:1911-1
SUSE-SU-2021:1928-1
SUSE-SU-2021:1956-1
SUSE-SU-2021_14744-1
SUSE-SU-2021_1901-1
SUSE-SU-2021_1902-1
SUSE-SU-2021_1905-1
SUSE-SU-2021_1911-1
SUSE-SU-2021_1928-1
SUSE-SU-2021_1956-1
USN-4572-1
USN-4572-2

Affected Products

Alt Linux
Centos
Linuxmint
Red Hat
Spice
Suse
Ubuntu
Spice-Gtk