ZeroHour

CVE-2020-14355

CVSS 3.1
6.6 medium
EPSS
3%p85
Published
()
Modified
Description

Multiple buffer overflow vulnerabilities were found in the QUIC image decoding process of the SPICE remote display system, before spice-0.14.2-1. Both the SPICE client (spice-gtk) and server are affected by these flaws. These flaws allow a malicious client or server to send specially crafted messages that, when processed by the QUIC image compression algorithm, result in a process crash or potential code execution.

Vendors
spice projectredhatcanonicaldebianopensuse
Products
spice, openstack, ubuntu linux, debian linux, leap, enterprise linux, enterprise linux aus, enterprise linux eus, enterprise linux tus, enterprise linux update services for sap solutions
Weakness
CWE-120
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L

In the news

No ingested article mentions this CVE yet.