[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248364

 
 

909

 
 

195388

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2020-25651Date: (C)2020-11-26   (M)2023-12-22


A flaw was found in the SPICE file transfer protocol. File data from the host system can end up in full or in parts in the client connection of an illegitimate local user in the VM system. Active file transfers from other users could also be interrupted, resulting in a denial of service. The highest threat from this vulnerability is to data confidentiality as well as system availability. This flaw affects spice-vdagent versions 0.20 and prior.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V3 Severity:CVSS V2 Severity:
CVSS Score : 6.4CVSS Score : 3.3
Exploit Score: 1.1Exploit Score: 3.4
Impact Score: 4.7Impact Score: 4.9
 
CVSS V3 Metrics:CVSS V2 Metrics:
Attack Vector: LOCALAccess Vector: LOCAL
Attack Complexity: HIGHAccess Complexity: MEDIUM
Privileges Required: LOWAuthentication: NONE
User Interaction: NONEConfidentiality: PARTIAL
Scope: CHANGEDIntegrity: NONE
Confidentiality: HIGHAvailability: PARTIAL
Integrity: NONE 
Availability: LOW 
  
Reference:
FEDORA-2021-09ce0cdfac
FEDORA-2021-510977db25
https://lists.debian.org/debian-lts-announce/2021/01/msg00012.html
https://bugzilla.redhat.com/show_bug.cgi?id=1886359
https://www.openwall.com/lists/oss-security/2020/11/04/1

CPE    1
cpe:/o:debian:debian_linux:9.0
CWE    1
CWE-362
OVAL    13
oval:org.secpod.oval:def:506085
oval:org.secpod.oval:def:70247
oval:org.secpod.oval:def:89045527
oval:org.secpod.oval:def:89045521
...

© SecPod Technologies