6.4
CVSSv3

CVE-2020-25651

Published: 26/11/2020 Updated: 07/11/2023
CVSS v2 Base Score: 3.3 | Impact Score: 4.9 | Exploitability Score: 3.4
CVSS v3 Base Score: 6.4 | Impact Score: 4.7 | Exploitability Score: 1.1
VMScore: 294
Vector: AV:L/AC:M/Au:N/C:P/I:N/A:P

Vulnerability Summary

A flaw was found in the SPICE file transfer protocol. File data from the host system can end up in full or in parts in the client connection of an illegitimate local user in the VM system. Active file transfers from other users could also be interrupted, resulting in a denial of service. The highest threat from this vulnerability is to data confidentiality as well as system availability. This flaw affects spice-vdagent versions 0.20 and prior.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

spice-space spice-vdagent

debian debian linux 9.0

fedoraproject fedora 32

fedoraproject fedora 33

Vendor Advisories

Debian Bug report logs - #973769 spice-vdagent: CVE-2020-25650 CVE-2020-25651 CVE-2020-25652 CVE-2020-25653 Package: src:spice-vdagent; Maintainer for src:spice-vdagent is Liang Guo <guoliang@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Wed, 4 Nov 2020 20:33:01 UTC Severity: grave Tags: s ...
A flaw was found in the SPICE file transfer protocol File data from the host system can end up in full or in parts in the client connection of an illegitimate local user in the VM system Active file transfers from other users could also be interrupted, resulting in a denial of service The highest threat from this vulnerability is to data confide ...