Back

MEDIUM

spice: multiple buffer overflow vulnerabilities in QUIC decoding code

Published Oct 7, 2020

Description

Multiple buffer overflow vulnerabilities were found in the QUIC image decoding process of the SPICE remote display system, before spice-0.14.2-1. Both the SPICE client (spice-gtk) and server are affected by these flaws. These flaws allow a malicious client or server to send specially crafted messages that, when processed by the QUIC image compression algorithm, result in a process crash or potential code execution.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (12)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Oct 7, 2020
Updated Aug 4, 2024
Reserved Jun 17, 2020
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Oct 6, 2020