First published: Tue Oct 06 2020(Updated: )
Frediano Ziglio discovered that Spice incorrectly handled QUIC image decoding. A remote attacker could use this to cause Spice to crash, resulting in a denial of service, or possibly execute arbitrary code.
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/libspice-server1 | <0.14.2-4ubuntu3.1 | 0.14.2-4ubuntu3.1 |
=20.04 | ||
All of | ||
ubuntu/libspice-server1 | <0.14.0-1ubuntu2.5 | 0.14.0-1ubuntu2.5 |
=18.04 | ||
All of | ||
ubuntu/libspice-server1 | <0.12.6-4ubuntu0.5 | 0.12.6-4ubuntu0.5 |
=16.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this security notice is USN-4572-1.
The title of the vulnerability is Spice vulnerability.
Frediano Ziglio discovered this vulnerability.
A remote attacker could exploit this vulnerability by causing Spice to crash, resulting in a denial of service or possibly executing arbitrary code.
Versions 0.14.2-4ubuntu3.1, 0.14.0-1ubuntu2.5, and 0.12.6-4ubuntu0.5 of libspice-server1 are affected by this vulnerability.
The remedy version for Ubuntu 20.04 is 0.14.2-4ubuntu3.1.
The remedy version for Ubuntu 18.04 is 0.14.0-1ubuntu2.5.
The remedy version for Ubuntu 16.04 is 0.12.6-4ubuntu0.5.
You can find more information about this vulnerability on the Ubuntu Security website.