Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Debian 9: DLA-2427-1 Critical: spice Remote Display Buffer Overflow

debian lts
Calendar Grey November 1, 2020
Dist Debian Esm H88
Enhance your spice software components to address various memory overflow vulnerabilities impacting the SPICE remote visualization framework in Debian.
Multiple buffer overflow vulnerabilities were found in the QUIC image decoding process of the SPICE remote display system, before spice-0.14.2-1

Summary

Both the SPICE client (spice-gtk) and server are affected by
these flaws. These flaws allow a malicious client or server to
send specially crafted messages that, when processed by the
QUIC image compression algorithm, result in a process crash
or potential code execution.

For Debian 9 stretch, this problem has been fixed in version
0.12.8-2.1+deb9u4.

We recommend that you upgrade your spice packages.

For the detailed security status of spice please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/source-package/spice

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS


Severity
critical
Lowest
Low
Medium
High
Critical

Package: spice
Version: 0.12.8-2.1+deb9u4
CVE ID: CVE-2020-14355
Debian Bug: 971750

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here