Re: [security-announce] openSUSE-SU-2020:1802-1: moderate: Security update for spice

Marcus Meissner <[email protected]> Fri, 26 Sep 2025 10:47:56 +0200
Newsgroups gmane.linux.suse.security
Organization SUSE Software Solutions Ger many GmbH, Frankenstraße 146, 90461 Nuernberg, Ger many, GF: Ivo Totev, Andrew Myers, Andrew McDonald , Martje Boudien Moerman, HRB 36809, AG Nürnberg
Message-ID <[email protected]>
Hi,

Sorry for this. I was approving these thinking they were genuine.

This should stop after the batch is released.

Ciao, Marcus

On Fri, Sep 26, 2025 at 11:37:35AM +0300, Cornel Diaconu wrote:
> Hi,
> please investigate what happened to the list distribution software, because
> since about 30 minutes or so, I (and most likely not only me, but all list
> members) were flooded with messages similar to this one -- very old
> announcements, like from 2021, 2020
> 
> Thanks
> 
> 
> On Fri, Sep 26, 2025 at 11:34 AM [email protected] <
> [email protected]> wrote:
> 
> >    openSUSE Security Update: Security update for spice
> > =5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=
> > =5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=
> > =5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=
> > =5F=5F=5F
> >
> > Announcement ID:    openSUSE-SU-2020:1802-1
> > Rating:             moderate
> > References:         #1177158
> > Cross-References:   CVE-2020-14355
> > Affected Products:
> >                     openSUSE Leap 15.2
> > =5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=
> > =5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=
> > =5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=
> > =5F=5F=5F
> >
> >    An update that fixes one vulnerability is now available.
> >
> > Description:
> >
> >    This update for spice fixes the following issues:
> >
> >    - CVE-2020-14355: Fixed multiple buffer overflow vulnerabilities in QUIC
> >      image decoding (bsc#1177158).
> >
> >    This update was imported from the SUSE:SLE-15-SP2:Update update project.
> >
> >
> > Patch Instructions:
> >
> >    To install this openSUSE Security Update use the SUSE recommended instal=
> > lation methods
> >    like YaST online=5Fupdate or "zypper patch".
> >
> >    Alternatively you can run the command listed for your product:
> >
> >    - openSUSE Leap 15.2:
> >
> >       zypper in -t patch openSUSE-2020-1802=3D1
> >
> >
> >
> > Package List:
> >
> >    - openSUSE Leap 15.2 (i586 x86=5F64):
> >
> >       libspice-server-devel-0.14.2-lp152.2.3.1
> >       libspice-server1-0.14.2-lp152.2.3.1
> >       libspice-server1-debuginfo-0.14.2-lp152.2.3.1
> >       spice-debugsource-0.14.2-lp152.2.3.1
> >
> >
> > References:
> >
> >    https://www.suse.com/security/cve/CVE-2020-14355.html
> >    https://bugzilla.suse.com/1177158
> >
> > --
> > To unsubscribe, e-mail: [email protected]
> > For additional commands, e-mail: [email protected]=
> > rg
> >
> >
> >
> 
> -- 
> With or without religion, good people can behave well and bad people can do
> evil; but for good people to do evil, that takes religion.
> [Steven Weinberg]
> We all know that light travels faster than sound. That's why certain people
> appear bright until you hear them speak.
> [Albert Einstein]

-- 
Marcus Meissner (he/him), Distinguished Engineer / Senior Project Manager Security
SUSE Software Solutions Germany GmbH, Frankenstrasse 146, 90461 Nuernberg, Germany
GF: Ivo Totev, Andrew McDonald, Werner Knoblich, HRB 36809, AG Nuernberg