CVE-2020-14355

Public on 2020-10-07
Modified on 2020-10-22
Description
Multiple buffer overflow vulnerabilities were found in the QUIC image decoding process of the SPICE remote display system. Both the SPICE client (spice-gtk) and server are affected by these flaws. These flaws allow a malicious client or server to send specially crafted messages that, when processed by the QUIC image compression algorithm, result in a process crash or potential code execution.
Severity
Important severity
Important
See what this means
CVSS v3 Base Score
6.6
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
Amazon Linux 2 - Core spice 2020-10-27 ALAS2-2020-1547 Fixed
Amazon Linux 2 - Core spice-gtk 2020-10-27 ALAS2-2020-1546 Fixed

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv3 6.6 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L
NVD CVSSv3 6.6 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L
NVD CVSSv2 6.5 AV:N/AC:L/Au:S/C:P/I:P/A:P