USN-4572-1: Spice vulnerability
Frediano Ziglio discovered that Spice incorrectly handled QUIC image decoding. A remote attacker could use this to cause Spice to crash, resulting in a denial of service, or possibly execute arbitrary code.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this security notice?
The vulnerability ID for this security notice is USN-4572-1.
What is the title of the vulnerability?
The title of the vulnerability is Spice vulnerability.
Who discovered this vulnerability?
Frediano Ziglio discovered this vulnerability.
How can a remote attacker exploit this vulnerability?
A remote attacker could exploit this vulnerability by causing Spice to crash, resulting in a denial of service or possibly executing arbitrary code.
Which versions of libspice-server1 are affected by this vulnerability?
Versions 0.14.2-4ubuntu3.1, 0.14.0-1ubuntu2.5, and 0.12.6-4ubuntu0.5 of libspice-server1 are affected by this vulnerability.
What is the remedy version for Ubuntu 20.04?
The remedy version for Ubuntu 20.04 is 0.14.2-4ubuntu3.1.
What is the remedy version for Ubuntu 18.04?
The remedy version for Ubuntu 18.04 is 0.14.0-1ubuntu2.5.
What is the remedy version for Ubuntu 16.04?
The remedy version for Ubuntu 16.04 is 0.12.6-4ubuntu0.5.
Where can I find more information about this vulnerability?
You can find more information about this vulnerability on the Ubuntu Security website.