SUSE-SU-2021:2803-1
Dashboard / Vulnerabilities / SUSE-SU-2021:2803-1
SUSE-SU-2021:2803-1
Summary: Security update for spice-vdagent
Details: This update for spice-vdagent fixes the following issues: - CVE-2020-25650: memory DoS via arbitrary entries in `active_xfers` hash table (bsc#1177780) - CVE-2020-25651: possible file transfer DoS and information leak via `active_xfers` hash map (bsc#1177781) - CVE-2020-25652: possibility to exhaust file descriptors in `vdagentd` (bsc#1177782) - CVE-2020-25653: UNIX domain socket peer PID retrieved via `SO_PEERCRED` is subject to race condition (bsc#1177783)
References: https://www.suse.com/support/update/announcement/2021/suse-su-20212803-1/, https://bugzilla.suse.com/1177780, https://bugzilla.suse.com/1177781, https://bugzilla.suse.com/1177782, https://bugzilla.suse.com/1177783, https://www.suse.com/security/cve/CVE-2020-25650, https://www.suse.com/security/cve/CVE-2020-25651, https://www.suse.com/security/cve/CVE-2020-25652, https://www.suse.com/security/cve/CVE-2020-25653
Affected packages
Package
Name: spice-vdagent
Purl: pkg:rpm/suse/spice-vdagent&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-ESPOS
Affected ranges
Type: ECOSYSTEM
Events:
