{
  "document": {
    "aggregate_severity": {
      "namespace": "https://nvd.nist.gov/vuln-metrics/cvss",
      "text": "MEDIUM"
    },
    "category": "csaf_security_advisory",
    "csaf_version": "2.0",
    "distribution": {
      "tlp": {
        "label": "WHITE",
        "url": "https:/www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "text": "Multiple buffer overflow vulnerabilities were found in the QUIC image decoding process of the SPICE remote display system, before spice-0.14.2-1. Both the SPICE client (spice-gtk) and server are affected by these flaws. These flaws allow a malicious client or server to send specially crafted messages that, when processed by the QUIC image compression algorithm, result in a process crash or potential code execution.",
        "category": "general",
        "title": "Synopsis"
      }
    ],
    "publisher": {
      "issuing_authority": "openEuler security committee",
      "name": "openEuler",
      "namespace": "https://www.openeuler.org",
      "contact_details": "openeuler-security@openeuler.org",
      "category": "vendor"
    },
    "references": [
      {
        "summary": "https://nvd.nist.gov/vuln/detail/CVE-2020-14355",
        "category": "external",
        "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-14355"
      },
      {
        "summary": "CVE-2020-14355",
        "category": "self",
        "url": "https://openeuler.org/en/security/cve/detail?cveId=CVE-2020-14355&packageName=spice"
      },
      {
        "summary": "openEuler-SA-2021-1082",
        "category": "self",
        "url": "https://openeuler.org/en/security/security-bulletins/detail/?id=openEuler-SA-2021-1082"
      },
      {
        "summary": "CVE-2020-14355 vex file",
        "category": "self",
        "url": "https://repo.openeuler.org/security/data/csaf/cve/2020/csaf-openEuler-cve-2020-14355.json"
      }
    ],
    "title": "openEuler cve CVE-2020-14355",
    "tracking": {
      "initial_release_date": "2025-06-11T10:51:27+08:00",
      "revision_history": [
        {
          "date": "2025-06-11T10:51:27+08:00",
          "summary": "Initial",
          "number": "1.0.0"
        }
      ],
      "generator": {
        "date": "2025-06-11T10:51:27+08:00",
        "engine": {
          "name": "openEuler CSAF Tool V1.0"
        }
      },
      "current_release_date": "2025-06-11T10:51:27+08:00",
      "id": "CVE-2020-14355",
      "version": "1.0.0",
      "status": "interim"
    }
  },
  "product_tree": {
    "branches": [
      {
        "name": "openEuler",
        "category": "vendor",
        "branches": [
          {
            "name": "openEuler",
            "branches": [
              {
                "product": {
                  "product_identification_helper": {
                    "cpe": "cpe:/a:openEuler:openEuler:20.03-LTS"
                  },
                  "product_id": "openEuler-20.03-LTS",
                  "name": "openEuler-20.03-LTS"
                },
                "name": "openEuler-20.03-LTS",
                "category": "product_version"
              },
              {
                "product": {
                  "product_identification_helper": {
                    "cpe": "cpe:/a:openEuler:openEuler:20.03-LTS-SP1"
                  },
                  "product_id": "openEuler-20.03-LTS-SP1",
                  "name": "openEuler-20.03-LTS-SP1"
                },
                "name": "openEuler-20.03-LTS-SP1",
                "category": "product_version"
              }
            ],
            "category": "product_name"
          },
          {
            "name": "aarch64",
            "branches": [
              {
                "product": {
                  "product_identification_helper": {
                    "cpe": "cpe:/a:openEuler:openEuler:20.03-LTS"
                  },
                  "product_id": "spice-server-devel-0.14.3-2.oe1.aarch64.rpm(20.03-LTS)",
                  "name": "spice-server-devel-0.14.3-2.oe1.aarch64.rpm"
                },
                "name": "spice-server-devel-0.14.3-2.oe1.aarch64.rpm",
                "category": "product_version"
              },
              {
                "product": {
                  "product_identification_helper": {
                    "cpe": "cpe:/a:openEuler:openEuler:20.03-LTS"
                  },
                  "product_id": "spice-debugsource-0.14.3-2.oe1.aarch64.rpm(20.03-LTS)",
                  "name": "spice-debugsource-0.14.3-2.oe1.aarch64.rpm"
                },
                "name": "spice-debugsource-0.14.3-2.oe1.aarch64.rpm",
                "category": "product_version"
              },
              {
                "product": {
                  "product_identification_helper": {
                    "cpe": "cpe:/a:openEuler:openEuler:20.03-LTS"
                  },
                  "product_id": "spice-debuginfo-0.14.3-2.oe1.aarch64.rpm(20.03-LTS)",
                  "name": "spice-debuginfo-0.14.3-2.oe1.aarch64.rpm"
                },
                "name": "spice-debuginfo-0.14.3-2.oe1.aarch64.rpm",
                "category": "product_version"
              },
              {
                "product": {
                  "product_identification_helper": {
                    "cpe": "cpe:/a:openEuler:openEuler:20.03-LTS"
                  },
                  "product_id": "spice-server-0.14.3-2.oe1.aarch64.rpm(20.03-LTS)",
                  "name": "spice-server-0.14.3-2.oe1.aarch64.rpm"
                },
                "name": "spice-server-0.14.3-2.oe1.aarch64.rpm",
                "category": "product_version"
              },
              {
                "product": {
                  "product_identification_helper": {
                    "cpe": "cpe:/a:openEuler:openEuler:20.03-LTS-SP1"
                  },
                  "product_id": "spice-server-devel-0.14.3-2.oe1.aarch64.rpm(20.03-LTS-SP1)",
                  "name": "spice-server-devel-0.14.3-2.oe1.aarch64.rpm"
                },
                "name": "spice-server-devel-0.14.3-2.oe1.aarch64.rpm",
                "category": "product_version"
              },
              {
                "product": {
                  "product_identification_helper": {
                    "cpe": "cpe:/a:openEuler:openEuler:20.03-LTS-SP1"
                  },
                  "product_id": "spice-debugsource-0.14.3-2.oe1.aarch64.rpm(20.03-LTS-SP1)",
                  "name": "spice-debugsource-0.14.3-2.oe1.aarch64.rpm"
                },
                "name": "spice-debugsource-0.14.3-2.oe1.aarch64.rpm",
                "category": "product_version"
              },
              {
                "product": {
                  "product_identification_helper": {
                    "cpe": "cpe:/a:openEuler:openEuler:20.03-LTS-SP1"
                  },
                  "product_id": "spice-debuginfo-0.14.3-2.oe1.aarch64.rpm(20.03-LTS-SP1)",
                  "name": "spice-debuginfo-0.14.3-2.oe1.aarch64.rpm"
                },
                "name": "spice-debuginfo-0.14.3-2.oe1.aarch64.rpm",
                "category": "product_version"
              },
              {
                "product": {
                  "product_identification_helper": {
                    "cpe": "cpe:/a:openEuler:openEuler:20.03-LTS-SP1"
                  },
                  "product_id": "spice-server-0.14.3-2.oe1.aarch64.rpm(20.03-LTS-SP1)",
                  "name": "spice-server-0.14.3-2.oe1.aarch64.rpm"
                },
                "name": "spice-server-0.14.3-2.oe1.aarch64.rpm",
                "category": "product_version"
              }
            ],
            "category": "architecture"
          },
          {
            "name": "noarch",
            "branches": [
              {
                "product": {
                  "product_identification_helper": {
                    "cpe": "cpe:/a:openEuler:openEuler:20.03-LTS"
                  },
                  "product_id": "spice-help-0.14.3-2.oe1.noarch.rpm(20.03-LTS)",
                  "name": "spice-help-0.14.3-2.oe1.noarch.rpm"
                },
                "name": "spice-help-0.14.3-2.oe1.noarch.rpm",
                "category": "product_version"
              },
              {
                "product": {
                  "product_identification_helper": {
                    "cpe": "cpe:/a:openEuler:openEuler:20.03-LTS-SP1"
                  },
                  "product_id": "spice-help-0.14.3-2.oe1.noarch.rpm(20.03-LTS-SP1)",
                  "name": "spice-help-0.14.3-2.oe1.noarch.rpm"
                },
                "name": "spice-help-0.14.3-2.oe1.noarch.rpm",
                "category": "product_version"
              }
            ],
            "category": "architecture"
          },
          {
            "name": "src",
            "branches": [
              {
                "product": {
                  "product_identification_helper": {
                    "cpe": "cpe:/a:openEuler:openEuler:20.03-LTS"
                  },
                  "product_id": "spice-0.14.3-2.oe1.src.rpm(20.03-LTS)",
                  "name": "spice-0.14.3-2.oe1.src.rpm"
                },
                "name": "spice-0.14.3-2.oe1.src.rpm",
                "category": "product_version"
              },
              {
                "product": {
                  "product_identification_helper": {
                    "cpe": "cpe:/a:openEuler:openEuler:20.03-LTS-SP1"
                  },
                  "product_id": "spice-0.14.3-2.oe1.src.rpm(20.03-LTS-SP1)",
                  "name": "spice-0.14.3-2.oe1.src.rpm"
                },
                "name": "spice-0.14.3-2.oe1.src.rpm",
                "category": "product_version"
              }
            ],
            "category": "architecture"
          },
          {
            "name": "x86_64",
            "branches": [
              {
                "product": {
                  "product_identification_helper": {
                    "cpe": "cpe:/a:openEuler:openEuler:20.03-LTS"
                  },
                  "product_id": "spice-debuginfo-0.14.3-2.oe1.x86_64.rpm(20.03-LTS)",
                  "name": "spice-debuginfo-0.14.3-2.oe1.x86_64.rpm"
                },
                "name": "spice-debuginfo-0.14.3-2.oe1.x86_64.rpm",
                "category": "product_version"
              },
              {
                "product": {
                  "product_identification_helper": {
                    "cpe": "cpe:/a:openEuler:openEuler:20.03-LTS"
                  },
                  "product_id": "spice-server-devel-0.14.3-2.oe1.x86_64.rpm(20.03-LTS)",
                  "name": "spice-server-devel-0.14.3-2.oe1.x86_64.rpm"
                },
                "name": "spice-server-devel-0.14.3-2.oe1.x86_64.rpm",
                "category": "product_version"
              },
              {
                "product": {
                  "product_identification_helper": {
                    "cpe": "cpe:/a:openEuler:openEuler:20.03-LTS"
                  },
                  "product_id": "spice-server-0.14.3-2.oe1.x86_64.rpm(20.03-LTS)",
                  "name": "spice-server-0.14.3-2.oe1.x86_64.rpm"
                },
                "name": "spice-server-0.14.3-2.oe1.x86_64.rpm",
                "category": "product_version"
              },
              {
                "product": {
                  "product_identification_helper": {
                    "cpe": "cpe:/a:openEuler:openEuler:20.03-LTS"
                  },
                  "product_id": "spice-debugsource-0.14.3-2.oe1.x86_64.rpm(20.03-LTS)",
                  "name": "spice-debugsource-0.14.3-2.oe1.x86_64.rpm"
                },
                "name": "spice-debugsource-0.14.3-2.oe1.x86_64.rpm",
                "category": "product_version"
              },
              {
                "product": {
                  "product_identification_helper": {
                    "cpe": "cpe:/a:openEuler:openEuler:20.03-LTS-SP1"
                  },
                  "product_id": "spice-debuginfo-0.14.3-2.oe1.x86_64.rpm(20.03-LTS-SP1)",
                  "name": "spice-debuginfo-0.14.3-2.oe1.x86_64.rpm"
                },
                "name": "spice-debuginfo-0.14.3-2.oe1.x86_64.rpm",
                "category": "product_version"
              },
              {
                "product": {
                  "product_identification_helper": {
                    "cpe": "cpe:/a:openEuler:openEuler:20.03-LTS-SP1"
                  },
                  "product_id": "spice-server-devel-0.14.3-2.oe1.x86_64.rpm(20.03-LTS-SP1)",
                  "name": "spice-server-devel-0.14.3-2.oe1.x86_64.rpm"
                },
                "name": "spice-server-devel-0.14.3-2.oe1.x86_64.rpm",
                "category": "product_version"
              },
              {
                "product": {
                  "product_identification_helper": {
                    "cpe": "cpe:/a:openEuler:openEuler:20.03-LTS-SP1"
                  },
                  "product_id": "spice-server-0.14.3-2.oe1.x86_64.rpm(20.03-LTS-SP1)",
                  "name": "spice-server-0.14.3-2.oe1.x86_64.rpm"
                },
                "name": "spice-server-0.14.3-2.oe1.x86_64.rpm",
                "category": "product_version"
              },
              {
                "product": {
                  "product_identification_helper": {
                    "cpe": "cpe:/a:openEuler:openEuler:20.03-LTS-SP1"
                  },
                  "product_id": "spice-debugsource-0.14.3-2.oe1.x86_64.rpm(20.03-LTS-SP1)",
                  "name": "spice-debugsource-0.14.3-2.oe1.x86_64.rpm"
                },
                "name": "spice-debugsource-0.14.3-2.oe1.x86_64.rpm",
                "category": "product_version"
              }
            ],
            "category": "architecture"
          }
        ]
      }
    ],
    "relationships": [
      {
        "relates_to_product_reference": "openEuler-20.03-LTS",
        "product_reference": "spice-server-devel-0.14.3-2.oe1.aarch64.rpm(20.03-LTS)",
        "full_product_name": {
          "product_id": "openEuler-20.03-LTS:spice-server-devel-0.14.3-2.oe1.aarch64",
          "name": "spice-server-devel-0.14.3-2.oe1.aarch64 as a component of openEuler-20.03-LTS"
        },
        "category": "default_component_of"
      },
      {
        "relates_to_product_reference": "openEuler-20.03-LTS",
        "product_reference": "spice-debugsource-0.14.3-2.oe1.aarch64.rpm(20.03-LTS)",
        "full_product_name": {
          "product_id": "openEuler-20.03-LTS:spice-debugsource-0.14.3-2.oe1.aarch64",
          "name": "spice-debugsource-0.14.3-2.oe1.aarch64 as a component of openEuler-20.03-LTS"
        },
        "category": "default_component_of"
      },
      {
        "relates_to_product_reference": "openEuler-20.03-LTS",
        "product_reference": "spice-debuginfo-0.14.3-2.oe1.aarch64.rpm(20.03-LTS)",
        "full_product_name": {
          "product_id": "openEuler-20.03-LTS:spice-debuginfo-0.14.3-2.oe1.aarch64",
          "name": "spice-debuginfo-0.14.3-2.oe1.aarch64 as a component of openEuler-20.03-LTS"
        },
        "category": "default_component_of"
      },
      {
        "relates_to_product_reference": "openEuler-20.03-LTS",
        "product_reference": "spice-server-0.14.3-2.oe1.aarch64.rpm(20.03-LTS)",
        "full_product_name": {
          "product_id": "openEuler-20.03-LTS:spice-server-0.14.3-2.oe1.aarch64",
          "name": "spice-server-0.14.3-2.oe1.aarch64 as a component of openEuler-20.03-LTS"
        },
        "category": "default_component_of"
      },
      {
        "relates_to_product_reference": "openEuler-20.03-LTS-SP1",
        "product_reference": "spice-server-devel-0.14.3-2.oe1.aarch64.rpm(20.03-LTS-SP1)",
        "full_product_name": {
          "product_id": "openEuler-20.03-LTS-SP1:spice-server-devel-0.14.3-2.oe1.aarch64",
          "name": "spice-server-devel-0.14.3-2.oe1.aarch64 as a component of openEuler-20.03-LTS-SP1"
        },
        "category": "default_component_of"
      },
      {
        "relates_to_product_reference": "openEuler-20.03-LTS-SP1",
        "product_reference": "spice-debugsource-0.14.3-2.oe1.aarch64.rpm(20.03-LTS-SP1)",
        "full_product_name": {
          "product_id": "openEuler-20.03-LTS-SP1:spice-debugsource-0.14.3-2.oe1.aarch64",
          "name": "spice-debugsource-0.14.3-2.oe1.aarch64 as a component of openEuler-20.03-LTS-SP1"
        },
        "category": "default_component_of"
      },
      {
        "relates_to_product_reference": "openEuler-20.03-LTS-SP1",
        "product_reference": "spice-debuginfo-0.14.3-2.oe1.aarch64.rpm(20.03-LTS-SP1)",
        "full_product_name": {
          "product_id": "openEuler-20.03-LTS-SP1:spice-debuginfo-0.14.3-2.oe1.aarch64",
          "name": "spice-debuginfo-0.14.3-2.oe1.aarch64 as a component of openEuler-20.03-LTS-SP1"
        },
        "category": "default_component_of"
      },
      {
        "relates_to_product_reference": "openEuler-20.03-LTS-SP1",
        "product_reference": "spice-server-0.14.3-2.oe1.aarch64.rpm(20.03-LTS-SP1)",
        "full_product_name": {
          "product_id": "openEuler-20.03-LTS-SP1:spice-server-0.14.3-2.oe1.aarch64",
          "name": "spice-server-0.14.3-2.oe1.aarch64 as a component of openEuler-20.03-LTS-SP1"
        },
        "category": "default_component_of"
      },
      {
        "relates_to_product_reference": "openEuler-20.03-LTS",
        "product_reference": "spice-help-0.14.3-2.oe1.noarch.rpm(20.03-LTS)",
        "full_product_name": {
          "product_id": "openEuler-20.03-LTS:spice-help-0.14.3-2.oe1.noarch",
          "name": "spice-help-0.14.3-2.oe1.noarch as a component of openEuler-20.03-LTS"
        },
        "category": "default_component_of"
      },
      {
        "relates_to_product_reference": "openEuler-20.03-LTS-SP1",
        "product_reference": "spice-help-0.14.3-2.oe1.noarch.rpm(20.03-LTS-SP1)",
        "full_product_name": {
          "product_id": "openEuler-20.03-LTS-SP1:spice-help-0.14.3-2.oe1.noarch",
          "name": "spice-help-0.14.3-2.oe1.noarch as a component of openEuler-20.03-LTS-SP1"
        },
        "category": "default_component_of"
      },
      {
        "relates_to_product_reference": "openEuler-20.03-LTS",
        "product_reference": "spice-0.14.3-2.oe1.src.rpm(20.03-LTS)",
        "full_product_name": {
          "product_id": "openEuler-20.03-LTS:spice-0.14.3-2.oe1.src",
          "name": "spice-0.14.3-2.oe1.src as a component of openEuler-20.03-LTS"
        },
        "category": "default_component_of"
      },
      {
        "relates_to_product_reference": "openEuler-20.03-LTS-SP1",
        "product_reference": "spice-0.14.3-2.oe1.src.rpm(20.03-LTS-SP1)",
        "full_product_name": {
          "product_id": "openEuler-20.03-LTS-SP1:spice-0.14.3-2.oe1.src",
          "name": "spice-0.14.3-2.oe1.src as a component of openEuler-20.03-LTS-SP1"
        },
        "category": "default_component_of"
      },
      {
        "relates_to_product_reference": "openEuler-20.03-LTS",
        "product_reference": "spice-debuginfo-0.14.3-2.oe1.x86_64.rpm(20.03-LTS)",
        "full_product_name": {
          "product_id": "openEuler-20.03-LTS:spice-debuginfo-0.14.3-2.oe1.x86_64",
          "name": "spice-debuginfo-0.14.3-2.oe1.x86_64 as a component of openEuler-20.03-LTS"
        },
        "category": "default_component_of"
      },
      {
        "relates_to_product_reference": "openEuler-20.03-LTS",
        "product_reference": "spice-server-devel-0.14.3-2.oe1.x86_64.rpm(20.03-LTS)",
        "full_product_name": {
          "product_id": "openEuler-20.03-LTS:spice-server-devel-0.14.3-2.oe1.x86_64",
          "name": "spice-server-devel-0.14.3-2.oe1.x86_64 as a component of openEuler-20.03-LTS"
        },
        "category": "default_component_of"
      },
      {
        "relates_to_product_reference": "openEuler-20.03-LTS",
        "product_reference": "spice-server-0.14.3-2.oe1.x86_64.rpm(20.03-LTS)",
        "full_product_name": {
          "product_id": "openEuler-20.03-LTS:spice-server-0.14.3-2.oe1.x86_64",
          "name": "spice-server-0.14.3-2.oe1.x86_64 as a component of openEuler-20.03-LTS"
        },
        "category": "default_component_of"
      },
      {
        "relates_to_product_reference": "openEuler-20.03-LTS",
        "product_reference": "spice-debugsource-0.14.3-2.oe1.x86_64.rpm(20.03-LTS)",
        "full_product_name": {
          "product_id": "openEuler-20.03-LTS:spice-debugsource-0.14.3-2.oe1.x86_64",
          "name": "spice-debugsource-0.14.3-2.oe1.x86_64 as a component of openEuler-20.03-LTS"
        },
        "category": "default_component_of"
      },
      {
        "relates_to_product_reference": "openEuler-20.03-LTS-SP1",
        "product_reference": "spice-debuginfo-0.14.3-2.oe1.x86_64.rpm(20.03-LTS-SP1)",
        "full_product_name": {
          "product_id": "openEuler-20.03-LTS-SP1:spice-debuginfo-0.14.3-2.oe1.x86_64",
          "name": "spice-debuginfo-0.14.3-2.oe1.x86_64 as a component of openEuler-20.03-LTS-SP1"
        },
        "category": "default_component_of"
      },
      {
        "relates_to_product_reference": "openEuler-20.03-LTS-SP1",
        "product_reference": "spice-server-devel-0.14.3-2.oe1.x86_64.rpm(20.03-LTS-SP1)",
        "full_product_name": {
          "product_id": "openEuler-20.03-LTS-SP1:spice-server-devel-0.14.3-2.oe1.x86_64",
          "name": "spice-server-devel-0.14.3-2.oe1.x86_64 as a component of openEuler-20.03-LTS-SP1"
        },
        "category": "default_component_of"
      },
      {
        "relates_to_product_reference": "openEuler-20.03-LTS-SP1",
        "product_reference": "spice-server-0.14.3-2.oe1.x86_64.rpm(20.03-LTS-SP1)",
        "full_product_name": {
          "product_id": "openEuler-20.03-LTS-SP1:spice-server-0.14.3-2.oe1.x86_64",
          "name": "spice-server-0.14.3-2.oe1.x86_64 as a component of openEuler-20.03-LTS-SP1"
        },
        "category": "default_component_of"
      },
      {
        "relates_to_product_reference": "openEuler-20.03-LTS-SP1",
        "product_reference": "spice-debugsource-0.14.3-2.oe1.x86_64.rpm(20.03-LTS-SP1)",
        "full_product_name": {
          "product_id": "openEuler-20.03-LTS-SP1:spice-debugsource-0.14.3-2.oe1.x86_64",
          "name": "spice-debugsource-0.14.3-2.oe1.x86_64 as a component of openEuler-20.03-LTS-SP1"
        },
        "category": "default_component_of"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2020-14355",
      "notes": [
        {
          "text": "Multiple buffer overflow vulnerabilities were found in the QUIC image decoding process of the SPICE remote display system, before spice-0.14.2-1. Both the SPICE client (spice-gtk) and server are affected by these flaws. These flaws allow a malicious client or server to send specially crafted messages that, when processed by the QUIC image compression algorithm, result in a process crash or potential code execution.",
          "category": "description",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "fixed": [
          "openEuler-20.03-LTS:spice-server-devel-0.14.3-2.oe1.aarch64",
          "openEuler-20.03-LTS:spice-debugsource-0.14.3-2.oe1.aarch64",
          "openEuler-20.03-LTS:spice-debuginfo-0.14.3-2.oe1.aarch64",
          "openEuler-20.03-LTS:spice-server-0.14.3-2.oe1.aarch64",
          "openEuler-20.03-LTS-SP1:spice-server-devel-0.14.3-2.oe1.aarch64",
          "openEuler-20.03-LTS-SP1:spice-debugsource-0.14.3-2.oe1.aarch64",
          "openEuler-20.03-LTS-SP1:spice-debuginfo-0.14.3-2.oe1.aarch64",
          "openEuler-20.03-LTS-SP1:spice-server-0.14.3-2.oe1.aarch64",
          "openEuler-20.03-LTS:spice-help-0.14.3-2.oe1.noarch",
          "openEuler-20.03-LTS-SP1:spice-help-0.14.3-2.oe1.noarch",
          "openEuler-20.03-LTS:spice-0.14.3-2.oe1.src",
          "openEuler-20.03-LTS-SP1:spice-0.14.3-2.oe1.src",
          "openEuler-20.03-LTS:spice-debuginfo-0.14.3-2.oe1.x86_64",
          "openEuler-20.03-LTS:spice-server-devel-0.14.3-2.oe1.x86_64",
          "openEuler-20.03-LTS:spice-server-0.14.3-2.oe1.x86_64",
          "openEuler-20.03-LTS:spice-debugsource-0.14.3-2.oe1.x86_64",
          "openEuler-20.03-LTS-SP1:spice-debuginfo-0.14.3-2.oe1.x86_64",
          "openEuler-20.03-LTS-SP1:spice-server-devel-0.14.3-2.oe1.x86_64",
          "openEuler-20.03-LTS-SP1:spice-server-0.14.3-2.oe1.x86_64",
          "openEuler-20.03-LTS-SP1:spice-debugsource-0.14.3-2.oe1.x86_64"
        ]
      },
      "remediations": [
        {
          "product_ids": [
            "openEuler-20.03-LTS:spice-server-devel-0.14.3-2.oe1.aarch64",
            "openEuler-20.03-LTS:spice-debugsource-0.14.3-2.oe1.aarch64",
            "openEuler-20.03-LTS:spice-debuginfo-0.14.3-2.oe1.aarch64",
            "openEuler-20.03-LTS:spice-server-0.14.3-2.oe1.aarch64",
            "openEuler-20.03-LTS-SP1:spice-server-devel-0.14.3-2.oe1.aarch64",
            "openEuler-20.03-LTS-SP1:spice-debugsource-0.14.3-2.oe1.aarch64",
            "openEuler-20.03-LTS-SP1:spice-debuginfo-0.14.3-2.oe1.aarch64",
            "openEuler-20.03-LTS-SP1:spice-server-0.14.3-2.oe1.aarch64",
            "openEuler-20.03-LTS:spice-help-0.14.3-2.oe1.noarch",
            "openEuler-20.03-LTS-SP1:spice-help-0.14.3-2.oe1.noarch",
            "openEuler-20.03-LTS:spice-0.14.3-2.oe1.src",
            "openEuler-20.03-LTS-SP1:spice-0.14.3-2.oe1.src",
            "openEuler-20.03-LTS:spice-debuginfo-0.14.3-2.oe1.x86_64",
            "openEuler-20.03-LTS:spice-server-devel-0.14.3-2.oe1.x86_64",
            "openEuler-20.03-LTS:spice-server-0.14.3-2.oe1.x86_64",
            "openEuler-20.03-LTS:spice-debugsource-0.14.3-2.oe1.x86_64",
            "openEuler-20.03-LTS-SP1:spice-debuginfo-0.14.3-2.oe1.x86_64",
            "openEuler-20.03-LTS-SP1:spice-server-devel-0.14.3-2.oe1.x86_64",
            "openEuler-20.03-LTS-SP1:spice-server-0.14.3-2.oe1.x86_64",
            "openEuler-20.03-LTS-SP1:spice-debugsource-0.14.3-2.oe1.x86_64"
          ],
          "details": "spice security update",
          "category": "vendor_fix",
          "url": "https://openeuler.org/en/security/security-bulletins/detail/?id=openEuler-SA-2021-1082"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseSeverity": "MEDIUM",
            "baseScore": 6.6,
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L",
            "version": "3.1"
          },
          "products": [
            "openEuler-20.03-LTS:spice-server-devel-0.14.3-2.oe1.aarch64",
            "openEuler-20.03-LTS:spice-debugsource-0.14.3-2.oe1.aarch64",
            "openEuler-20.03-LTS:spice-debuginfo-0.14.3-2.oe1.aarch64",
            "openEuler-20.03-LTS:spice-server-0.14.3-2.oe1.aarch64",
            "openEuler-20.03-LTS-SP1:spice-server-devel-0.14.3-2.oe1.aarch64",
            "openEuler-20.03-LTS-SP1:spice-debugsource-0.14.3-2.oe1.aarch64",
            "openEuler-20.03-LTS-SP1:spice-debuginfo-0.14.3-2.oe1.aarch64",
            "openEuler-20.03-LTS-SP1:spice-server-0.14.3-2.oe1.aarch64",
            "openEuler-20.03-LTS:spice-help-0.14.3-2.oe1.noarch",
            "openEuler-20.03-LTS-SP1:spice-help-0.14.3-2.oe1.noarch",
            "openEuler-20.03-LTS:spice-0.14.3-2.oe1.src",
            "openEuler-20.03-LTS-SP1:spice-0.14.3-2.oe1.src",
            "openEuler-20.03-LTS:spice-debuginfo-0.14.3-2.oe1.x86_64",
            "openEuler-20.03-LTS:spice-server-devel-0.14.3-2.oe1.x86_64",
            "openEuler-20.03-LTS:spice-server-0.14.3-2.oe1.x86_64",
            "openEuler-20.03-LTS:spice-debugsource-0.14.3-2.oe1.x86_64",
            "openEuler-20.03-LTS-SP1:spice-debuginfo-0.14.3-2.oe1.x86_64",
            "openEuler-20.03-LTS-SP1:spice-server-devel-0.14.3-2.oe1.x86_64",
            "openEuler-20.03-LTS-SP1:spice-server-0.14.3-2.oe1.x86_64",
            "openEuler-20.03-LTS-SP1:spice-debugsource-0.14.3-2.oe1.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "details": "Medium",
          "category": "impact"
        }
      ],
      "title": "CVE-2020-14355"
    }
  ]
}