|
|
Subscribe / Log in / New account

Debian alert DLA-2428-1 (spice-gtk)

From:  Utkarsh Gupta <utkarsh@debian.org>
To:  debian-lts-announce@lists.debian.org
Subject:  [SECURITY] [DLA 2428-1] spice-gtk security update
Date:  Sun, 01 Nov 2020 22:39:07 +0530
Message-ID:   <CAPP0f94gLk9QRduwJBHjPNqmkYQwx=s8J+jC8p=aW5=5N14DOw@mail.gmail.com>

-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 - ----------------------------------------------------------------------- Debian LTS Advisory DLA-2428-1 debian-lts@lists.debian.org https://www.debian.org/lts/security/ Utkarsh Gupta November 01, 2020 https://wiki.debian.org/LTS - ----------------------------------------------------------------------- Package : spice-gtk Version : 0.33-3.3+deb9u2 CVE ID : CVE-2020-14355 Debian Bug : 971751 Multiple buffer overflow vulnerabilities were found in the QUIC image decoding process of the SPICE remote display system. Both the SPICE client (spice-gtk) and server are affected by these flaws. These flaws allow a malicious client or server to send specially crafted messages that, when processed by the QUIC image compression algorithm, result in a process crash or potential code execution. For Debian 9 stretch, this problem has been fixed in version 0.33-3.3+deb9u2. We recommend that you upgrade your spice-gtk packages. For the detailed security status of spice-gtk please refer to its security tracker page at: https://security-tracker.debian.org/tracker/spice-gtk Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEbJ0QSEqa5Mw4X3xxgj6WdgbDS5YFAl+e62wACgkQgj6WdgbD S5ZJZxAAtCwyFoGQ8ggJN50y8kWOPSKlPwJtPjjxwOV7CPsaWX4PlQ8TJiKX85u3 r5I+CwTID8De/pmLVRlf8fHslz0TvqPwZkdiDybgyiIfWPd0l78MxZEZmH+HheP3 jh6A9PF1kewp8i/s957X9QVlDLnkpPfBAIZfnzLhqWB873RzYXIXlcraHERTDOKo JC+IaCmpXebNpSanXEKstOndwqjA8m5DmoOaUMWM8eeQPi9QoYh40z6JyBZDAAXZ pNVqXN0GMDpfGkTQ8qtVCebtD/hkOruNUQO1qJSPCxfvUygzC7RrAfMBZiu3cuQA yewjoaE3UyljCGYHJfb8aGv3sueNbQRwa9sOATPvUCAvo9vAGE9ezFdDk8w/qYyW 0XnKGL6fCKdfVARWSsEjNw/9Ljf4AK/iUS2kt/5OeYqH5e5I6IBcOxMIBASC09G3 94x6UfTzqKY4Z5mhRjr60J1r8glmDzRRkSf3f28USs494Uv4Mi5QaymTzJO3qKVy Hu5fVswi8HBKzbeyKVi1wrp/xgurWH56mgs9M0uc3gfgELSOToKeT6ag97di090I t1gJ49PJ4kPzAsMqf4f03erfmFtiz7Rn+FHSKngOXlBnE2bWMenUyMsy4elutsiW BHsgRbFjr6hRx5x/orIrg6pgeeTJyF+HnmbwuxqXKxwKe45La4A= =xm0z -----END PGP SIGNATURE-----


to post comments


Copyright © 2025, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds