Source: spice
Version: 0.14.3-1
Severity: grave
Tags: security upstream
X-Debbugs-Cc: car...@debian.org, Debian Security Team <t...@security.debian.org>
Control: clone -1 -2
Control: reassign -2 spice-gtk 0.38-2
Control: retitle -2 spice-gtk: CVE-2020-14355
Control: found -1 0.14.0-1.3
Control: found -2 0.35-2

Hi,

The following vulnerability was published for spice and spice-gtk (as
the issue reside in the spice-common shared code).

CVE-2020-14355[0]:
| Multiple buffer overflow vulnerabilities were found in the QUIC image
| decoding process of the SPICE remote display system.

If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2020-14355
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-14355

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

Reply via email to