PT-2020-6186 · Red Hat+5 · Spice+7
Frediano Ziglio
·
Published
2019-06-03
·
Updated
2024-06-15
·
CVE-2020-14355
CVSS v3.1
6.6
Medium
| Vector | AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
SPICE versions prior to 0.14.2-1
spice-gtk versions prior to 0.14.2-1
Description
The issue is related to buffer overflow vulnerabilities in the QUIC image decoding process of the SPICE remote display system. These vulnerabilities can be exploited by a malicious client or server sending specially crafted messages, which can result in a process crash or potential code execution when processed by the QUIC image compression algorithm. This could allow an attacker to access confidential data, compromise its integrity, and cause a denial of service.
Recommendations
For SPICE versions prior to 0.14.2-1, update to version 0.14.2-1 or later to resolve the issue.
For spice-gtk versions prior to 0.14.2-1, update to version 0.14.2-1 or later to resolve the issue.
As a temporary workaround, consider restricting access to the QUIC image decoding process until a patch is available.
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Centos
Linuxmint
Red Hat
Spice
Suse
Ubuntu
Spice-Gtk