{"api_version":"1","generated_at":"2026-07-23T15:45:32+00:00","cve":"CVE-2020-25651","urls":{"html":"https://cve.report/CVE-2020-25651","api":"https://cve.report/api/cve/CVE-2020-25651.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2020-25651","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2020-25651"},"summary":{"title":"CVE-2020-25651","description":"A flaw was found in the SPICE file transfer protocol. File data from the host system can end up in full or in parts in the client connection of an illegitimate local user in the VM system. Active file transfers from other users could also be interrupted, resulting in a denial of service. The highest threat from this vulnerability is to data confidentiality as well as system availability. This flaw affects spice-vdagent versions 0.20 and prior.","state":"PUBLIC","assigner":"secalert@redhat.com","published_at":"2020-11-26 02:15:00","updated_at":"2023-11-07 03:20:00"},"problem_types":["CWE-362"],"metrics":[],"references":[{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GQT56LATVTB2DJOVVJOKQVMVUXYCT2VB/","name":"FEDORA-2021-510977db25","refsource":"","tags":[],"title":"[SECURITY] Fedora 32 Update: spice-vdagent-0.21.0-1.fc32 - package-announce - Fedora Mailing-Lists","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OIWJ2EIQXWEA2VDBODEATHAT37X4CREP/","name":"FEDORA-2021-09ce0cdfac","refsource":"","tags":[],"title":"[SECURITY] Fedora 33 Update: spice-vdagent-0.21.0-1.fc33 - package-announce - Fedora Mailing-Lists","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.openwall.com/lists/oss-security/2020/11/04/1","name":"https://www.openwall.com/lists/oss-security/2020/11/04/1","refsource":"MISC","tags":["Exploit","Mailing List","Third Party Advisory"],"title":"oss-security - Security Issues in the spice-vdagentd daemon","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OIWJ2EIQXWEA2VDBODEATHAT37X4CREP/","name":"FEDORA-2021-09ce0cdfac","refsource":"FEDORA","tags":["Third Party Advisory"],"title":"[SECURITY] Fedora 33 Update: spice-vdagent-0.21.0-1.fc33 - package-announce - Fedora Mailing-Lists","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GQT56LATVTB2DJOVVJOKQVMVUXYCT2VB/","name":"FEDORA-2021-510977db25","refsource":"FEDORA","tags":["Third Party Advisory"],"title":"[SECURITY] Fedora 32 Update: spice-vdagent-0.21.0-1.fc32 - package-announce - Fedora Mailing-Lists","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=1886359","name":"https://bugzilla.redhat.com/show_bug.cgi?id=1886359","refsource":"MISC","tags":["Issue Tracking","Patch","Third Party Advisory"],"title":"1886359 – (CVE-2020-25651) CVE-2020-25651 spice-vdagent: possible file transfer DoS and information leak via `active_xfers` hash map","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://lists.debian.org/debian-lts-announce/2021/01/msg00012.html","name":"[debian-lts-announce] 20210113 [SECURITY] [DLA 2524-1] spice-vdagent security update","refsource":"MLIST","tags":["Mailing List","Third Party Advisory"],"title":"[SECURITY] [DLA 2524-1] spice-vdagent security update","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2020-25651","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2020-25651","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2020","cve_id":"25651","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"debian","cpe5":"debian_linux","cpe6":"9.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2020","cve_id":"25651","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"debian","cpe5":"debian_linux","cpe6":"9.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2020","cve_id":"25651","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"fedoraproject","cpe5":"fedora","cpe6":"32","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2020","cve_id":"25651","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"fedoraproject","cpe5":"fedora","cpe6":"33","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2020","cve_id":"25651","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"fedoraproject","cpe5":"fedora","cpe6":"32","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2020","cve_id":"25651","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"fedoraproject","cpe5":"fedora","cpe6":"33","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2020","cve_id":"25651","vulnerable":"1","versionEndIncluding":"0.20.0","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"spice-space","cpe5":"spice-vdagent","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2020-25651","qid":"159216","title":"Oracle Enterprise Linux Security Update for spice-vdagent (ELSA-2021-1791)"},{"cve":"CVE-2020-25651","qid":"239302","title":"Red Hat Update for spice-vdagent (RHSA-2021:1791)"},{"cve":"CVE-2020-25651","qid":"377381","title":"Alibaba Cloud Linux Security Update for spice-vdagent (ALINUX3-SA-2022:0084)"},{"cve":"CVE-2020-25651","qid":"670499","title":"EulerOS Security Update for spice-vdagent (EulerOS-SA-2021-2257)"},{"cve":"CVE-2020-25651","qid":"670525","title":"EulerOS Security Update for spice-vdagent (EulerOS-SA-2021-2283)"},{"cve":"CVE-2020-25651","qid":"670557","title":"EulerOS Security Update for spice-vdagent (EulerOS-SA-2021-2316)"},{"cve":"CVE-2020-25651","qid":"670592","title":"EulerOS Security Update for spice-vdagent (EulerOS-SA-2021-2350)"},{"cve":"CVE-2020-25651","qid":"670694","title":"EulerOS Security Update for spice-vdagent (EulerOS-SA-2021-2452)"},{"cve":"CVE-2020-25651","qid":"670962","title":"EulerOS Security Update for spice-vdagent (EulerOS-SA-2021-2617)"},{"cve":"CVE-2020-25651","qid":"750925","title":"OpenSUSE Security Update for spice-vdagent (openSUSE-SU-2021:2614-1)"},{"cve":"CVE-2020-25651","qid":"750974","title":"SUSE Enterprise Linux Security Update for spice-vdagent (SUSE-SU-2021:2766-1)"},{"cve":"CVE-2020-25651","qid":"750989","title":"SUSE Enterprise Linux Security Update for spice-vdagent (SUSE-SU-2021:2803-1)"},{"cve":"CVE-2020-25651","qid":"901686","title":"Common Base Linux Mariner (CBL-Mariner) Security Update for spice-vdagent (7363-1)"},{"cve":"CVE-2020-25651","qid":"940204","title":"AlmaLinux Security Update for spice-vdagent (ALSA-2021:1791)"},{"cve":"CVE-2020-25651","qid":"960751","title":"Rocky Linux Security Update for spice-vdagent (RLSA-2021:1791)"}]},"source_records":{"cve_program":{"data_type":"CVE","data_format":"MITRE","data_version":"4.0","CVE_data_meta":{"ID":"CVE-2020-25651","ASSIGNER":"secalert@redhat.com","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"vendor_name":"n/a","product":{"product_data":[{"product_name":"spice-vdagent","version":{"version_data":[{"version_value":"spice-vdagent versions 0.20 and prior"}]}}]}}]}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-362->CWE-200"}]}]},"references":{"reference_data":[{"refsource":"MISC","name":"https://www.openwall.com/lists/oss-security/2020/11/04/1","url":"https://www.openwall.com/lists/oss-security/2020/11/04/1"},{"refsource":"MISC","name":"https://bugzilla.redhat.com/show_bug.cgi?id=1886359","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1886359"},{"refsource":"MLIST","name":"[debian-lts-announce] 20210113 [SECURITY] [DLA 2524-1] spice-vdagent security update","url":"https://lists.debian.org/debian-lts-announce/2021/01/msg00012.html"},{"refsource":"FEDORA","name":"FEDORA-2021-09ce0cdfac","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OIWJ2EIQXWEA2VDBODEATHAT37X4CREP/"},{"refsource":"FEDORA","name":"FEDORA-2021-510977db25","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GQT56LATVTB2DJOVVJOKQVMVUXYCT2VB/"}]},"description":{"description_data":[{"lang":"eng","value":"A flaw was found in the SPICE file transfer protocol. File data from the host system can end up in full or in parts in the client connection of an illegitimate local user in the VM system. Active file transfers from other users could also be interrupted, resulting in a denial of service. The highest threat from this vulnerability is to data confidentiality as well as system availability. This flaw affects spice-vdagent versions 0.20 and prior."}]}},"nvd":{"publishedDate":"2020-11-26 02:15:00","lastModifiedDate":"2023-11-07 03:20:00","problem_types":["CWE-362"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:L","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"LOW","baseScore":6.4,"baseSeverity":"MEDIUM"},"exploitabilityScore":1.1,"impactScore":4.7},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:L/AC:M/Au:N/C:P/I:N/A:P","accessVector":"LOCAL","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"PARTIAL","baseScore":3.3},"severity":"LOW","exploitabilityScore":3.4,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:spice-space:spice-vdagent:*:*:*:*:*:*:*:*","versionEndIncluding":"0.20.0","cpe_name":[]}]},{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*","cpe_name":[]}]},{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2020","CveId":"25651","Ordinal":"187068","Title":"CVE-2020-25651","CVE":"CVE-2020-25651","Year":"2020"},"notes":[{"CveYear":"2020","CveId":"25651","Ordinal":"1","NoteData":"A flaw was found in the SPICE file transfer protocol. File data from the host system can end up in full or in parts in the client connection of an illegitimate local user in the VM system. Active file transfers from other users could also be interrupted, resulting in a denial of service. The highest threat from this vulnerability is to data confidentiality as well as system availability. This flaw affects spice-vdagent versions 0.20 and prior.","Type":"Description","Title":null},{"CveYear":"2020","CveId":"25651","Ordinal":"2","NoteData":"2020-11-25","Type":"Other","Title":"Published"},{"CveYear":"2020","CveId":"25651","Ordinal":"3","NoteData":"2021-02-17","Type":"Other","Title":"Modified"}]}}}