spice 0.14.0-1ubuntu2.5 source package in Ubuntu

Changelog

spice (0.14.0-1ubuntu2.5) bionic-security; urgency=medium

  * SECURITY UPDATE: multiple buffer overflows in QUIC image decoding
    - debian/patches/CVE-2020-14355-1.patch: check we have some data to
      start decoding quic image in spice-common/common/quic.c.
    - debian/patches/CVE-2020-14355-2.patch: check image size in
      quic_decode_begin in spice-common/common/quic.c.
    - debian/patches/CVE-2020-14355-3.patch: check RLE lengths in
      spice-common/common/quic_tmpl.c.
    - debian/patches/CVE-2020-14355-4.patch: avoid possible buffer overflow
      in find_bucket in spice-common/common/quic_family_tmpl.c.
    - CVE-2020-14355

 -- Marc Deslauriers <email address hidden>  Thu, 01 Oct 2020 07:12:53 -0400

Upload details

Uploaded by:
Marc Deslauriers
Uploaded to:
Bionic
Original maintainer:
Ubuntu Developers
Architectures:
alpha amd64 arm64 armel armhf i386 mips64el mipsel ppc64el sh4 x32
Section:
misc
Urgency:
Medium Urgency

See full publishing history Publishing

Series Pocket Published Component Section
Bionic updates main misc
Bionic security main misc

Downloads

File Size SHA-256 Checksum
spice_0.14.0.orig.tar.bz2 1.3 MiB 3adb9495b51650e5eab53c74dd6a74919af4b339ff21721d9ab2a45b2e3bb848
spice_0.14.0-1ubuntu2.5.debian.tar.xz 20.7 KiB 27485c356476f55c3ccca6d2b24d17fb876daff3f66922f4c172bd23b5fe6b01
spice_0.14.0-1ubuntu2.5.dsc 2.7 KiB 58c4a1e73a09ae940d077ebc1366a7f16ece25de99c4bab3c841a85c00404d38

View changes file

Binary packages built by this source

libspice-server-dev: Header files and development documentation for spice-server

 The Simple Protocol for Independent Computing Environments (SPICE) is
 a remote display system built for virtual environments which allows
 you to view a computing 'desktop' environment not only on the machine
 where it is running, but from anywhere on the Internet and from a wide
 variety of machine architectures.
 .
 This package contains the header files, static libraries and development
 documentation for spice-server.

libspice-server1: Implements the server side of the SPICE protocol

 The Simple Protocol for Independent Computing Environments (SPICE) is
 a remote display system built for virtual environments which allows
 you to view a computing 'desktop' environment not only on the machine
 where it is running, but from anywhere on the Internet and from a wide
 variety of machine architectures.
 .
 This package contains the run-time libraries for any application that
 wishes to be a SPICE server.

libspice-server1-dbgsym: debug symbols for libspice-server1