A flaw was found in spice in versions before 0.14.92. A DoS tool might make it easier for remote attackers to cause a denial of service (CPU consumption) by performing many renegotiations within a single connection.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Spice | Spice_project | * | 0.14.92 (excluding) |
Red Hat Enterprise Linux 8 | RedHat | spice-0:0.14.3-4.el8 | * |
Spice | Ubuntu | bionic | * |
Spice | Ubuntu | esm-infra/bionic | * |
Spice | Ubuntu | focal | * |
Spice | Ubuntu | groovy | * |
Spice | Ubuntu | hirsute | * |
Spice | Ubuntu | impish | * |
Spice | Ubuntu | kinetic | * |
Spice | Ubuntu | lunar | * |
Spice | Ubuntu | mantic | * |
Spice | Ubuntu | trusty | * |
Spice | Ubuntu | trusty/esm | * |
Spice | Ubuntu | upstream | * |
Spice | Ubuntu | xenial | * |
Spice-gtk | Ubuntu | trusty | * |
Spice-protocol | Ubuntu | trusty | * |