QID 671046

Date Published: 2021-11-30

QID 671046: EulerOS Security Update for spice (EulerOS-SA-2021-2616)

The simple protocol for independent computing environments (spice) is a remote display system built for virtual environments which allows you to view a computing 'desktop' environment not only on the machine where it is running, but from anywhere on the internet and from a wide variety of machine architectures.
Security fix(es): a flaw was found in spice in versions before 0.14.92.
A dos tool might make it easier for remote attackers to cause a denial of service (cpu consumption) by performing many renegotiations within a single connection.(cve-2021-20201)

Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.

An arbitrary attacker may exploit this vulnerability to compromise the system.

  • CVSS V3 rated as Medium - 5.3 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    The Vendor has released a security update to fix the vulnerability. For more information please visit EulerOS-SA-2021-2616 for updates and patch information

    CVEs related to QID 671046

    Software Advisories
    Advisory ID Software Component Link
    EulerOS-SA-2021-2616 EulerOS V2.0SP3 URL Logo developer.huaweicloud.com/ict/en/site-euleros/euleros/security-advisories/EulerOS-SA-2021-2616