Rapid7 Vulnerability & Exploit Database

Red Hat: CVE-2020-14355: CVE-2020-14355 spice: multiple buffer overflow vulnerabilities in QUIC decoding code (Multiple Advisories)

Free InsightVM Trial No Credit Card Necessary
2024 Attack Intel Report Latest research by Rapid7 Labs
Back to Search

Red Hat: CVE-2020-14355: CVE-2020-14355 spice: multiple buffer overflow vulnerabilities in QUIC decoding code (Multiple Advisories)

Severity
7
CVSS
(AV:N/AC:L/Au:S/C:P/I:P/A:P)
Published
10/06/2020
Created
10/08/2020
Added
10/07/2020
Modified
12/15/2023

Description

Multiple buffer overflow vulnerabilities were found in the QUIC image decoding process of the SPICE remote display system, before spice-0.14.2-1. Both the SPICE client (spice-gtk) and server are affected by these flaws. These flaws allow a malicious client or server to send specially crafted messages that, when processed by the QUIC image compression algorithm, result in a process crash or potential code execution.

Solution(s)

  • redhat-upgrade-spice-debuginfo
  • redhat-upgrade-spice-debugsource
  • redhat-upgrade-spice-glib
  • redhat-upgrade-spice-glib-debuginfo
  • redhat-upgrade-spice-glib-devel
  • redhat-upgrade-spice-gtk
  • redhat-upgrade-spice-gtk-debuginfo
  • redhat-upgrade-spice-gtk-debugsource
  • redhat-upgrade-spice-gtk-tools
  • redhat-upgrade-spice-gtk-tools-debuginfo
  • redhat-upgrade-spice-gtk3
  • redhat-upgrade-spice-gtk3-debuginfo
  • redhat-upgrade-spice-gtk3-devel
  • redhat-upgrade-spice-gtk3-vala
  • redhat-upgrade-spice-server
  • redhat-upgrade-spice-server-debuginfo
  • redhat-upgrade-spice-server-devel

With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.

– Scott Cheney, Manager of Information Security, Sierra View Medical Center

;