CVE-2021-20201
28.05.2021, 11:15
A flaw was found in spice in versions before 0.14.92. A DoS tool might make it easier for remote attackers to cause a denial of service (CPU consumption) by performing many renegotiations within a single connection.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| spice_project | spice | 𝑥 < 0.14.92 |
| redhat | enterprise_linux | 6.0 |
| redhat | enterprise_linux | 7.0 |
| redhat | enterprise_linux | 8.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| spice |
| ||||||||||||||||||||||||
| spice-gtk |
| ||||||||||||||||||||||||
| spice-protocol |
|
openSUSE / SLES Releases
openSUSE Product | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| libspice-client-glib-2_0-8 |
| ||||||||||||||||||||||||
| libspice-client-glib-helper |
| ||||||||||||||||||||||||
| libspice-client-gtk-3_0-5 |
| ||||||||||||||||||||||||
| libspice-server-devel |
| ||||||||||||||||||||||||
| libspice-server1 |
| ||||||||||||||||||||||||
| spice-gtk-devel |
| ||||||||||||||||||||||||
| typelib-1_0-SpiceClientGlib-2_0 |
| ||||||||||||||||||||||||
| typelib-1_0-SpiceClientGtk-3_0 |
|
Red Hat Enterprise Linux Releases
References