Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 491
Alerts This Week
Warning Icon 1 491

openSUSE 15.2: 2020:1802-1 Moderate: Spice Buffer Overflow Fix

opensuse
Calendar Grey November 1, 2020
Scroller Opensuse
Corrects the address buffer overflow in spice for openSUSE, enhancing system security and ensuring operational reliability.
An update that fixes one vulnerability is now available.

Description

This update for spice fixes the following issues:

- CVE-2020-14355: Fixed multiple buffer overflow vulnerabilities in QUIC

image decoding (bsc#1177158).

This update was imported from the SUSE:SLE-15-SP2:Update update project.

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 15.2:

zypper in -t patch openSUSE-2020-1802=1

Package List

- openSUSE Leap 15.2 (i586 x86_64):

libspice-server-devel-0.14.2-lp152.2.3.1

libspice-server1-0.14.2-lp152.2.3.1

libspice-server1-debuginfo-0.14.2-lp152.2.3.1

spice-debugsource-0.14.2-lp152.2.3.1

References

https://www.suse.com/security/cve/CVE-2020-14355.html

https://bugzilla.suse.com/1177158

--

Announcement ID: openSUSE-SU-2020:1802-1
Rating: moderate
Affected Products: openSUSE Leap 15.2

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.