rpm package
suse/spice&distro=SUSE Linux Enterprise Server 11 SP4-LTSS
pkg:rpm/suse/spice&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4-LTSS
Vulnerabilities (3)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2021-20201 | — | < 0.12.4-21.1 | 0.12.4-21.1 | May 28, 2021 | A flaw was found in spice in versions before 0.14.92. A DoS tool might make it easier for remote attackers to cause a denial of service (CPU consumption) by performing many renegotiations within a single connection. | ||
| CVE-2020-14355 | — | < 0.12.4-21.1 | 0.12.4-21.1 | Oct 7, 2020 | Multiple buffer overflow vulnerabilities were found in the QUIC image decoding process of the SPICE remote display system, before spice-0.14.2-1. Both the SPICE client (spice-gtk) and server are affected by these flaws. These flaws allow a malicious client or server to send speci | ||
| CVE-2016-2150 | Hig | 7.1 | < 0.12.4-21.1 | 0.12.4-21.1 | Jun 9, 2016 | SPICE allows local guest OS users to read from or write to arbitrary host memory locations via crafted primary surface parameters, a similar issue to CVE-2015-5261. |
- CVE-2021-20201May 28, 2021affected < 0.12.4-21.1fixed 0.12.4-21.1
A flaw was found in spice in versions before 0.14.92. A DoS tool might make it easier for remote attackers to cause a denial of service (CPU consumption) by performing many renegotiations within a single connection.
- CVE-2020-14355Oct 7, 2020affected < 0.12.4-21.1fixed 0.12.4-21.1
Multiple buffer overflow vulnerabilities were found in the QUIC image decoding process of the SPICE remote display system, before spice-0.14.2-1. Both the SPICE client (spice-gtk) and server are affected by these flaws. These flaws allow a malicious client or server to send speci
- affected < 0.12.4-21.1fixed 0.12.4-21.1
SPICE allows local guest OS users to read from or write to arbitrary host memory locations via crafted primary surface parameters, a similar issue to CVE-2015-5261.