CVE-2021-20201 PUBLISHED

A flaw was found in spice in versions before 0.14.92. A DoS tool might make it easier for remote attackers to cause a denial of service (CPU consumption) by performing many renegotiations within a single connection.

EPSS 0.73% · 72.5th percentile

Risk Scores

EPSS Score
0.73%
72.5th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:14.04:LTSspice0.12.4-0nocelt2ubuntu1.4, 0.12.4-0nocelt2ubuntu1.5, 0.12.4-0nocelt2ubuntu1.6
Ubuntu:20.04:LTSspice0, 0.14.2-0ubuntu2, 0.14.2-4ubuntu1
Ubuntu:18.04:LTSspice0.14.0-1ubuntu2.5, 0, 0.12.8-2.2
Ubuntu:16.04:LTSspice0.12.5-1.1ubuntu2, 0.12.6-4, 0.12.6-4ubuntu0.1

Timeline

References

Open in Interactive Console →