CVE-2020-7039
16.01.2020, 23:15
tcp_emu in tcp_subr.c in libslirp 4.1.0, as used in QEMU 4.2.0, mismanages memory, as demonstrated by IRC DCC commands in EMU_IRC. This can cause a heap-based buffer overflow or other out-of-bounds access which can lead to a DoS or potential execute arbitrary code.Enginsight
Vendor | Product | Version |
---|---|---|
libslirp_project | libslirp | 4.1.0 |
qemu | qemu | 4.2.0 |
debian | debian_linux | 8.0 |
debian | debian_linux | 9.0 |
opensuse | leap | 15.1 |
𝑥
= Vulnerable software versions

Debian Releases
Debian Product | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|
libslirp |
| ||||||||||
qemu |
| ||||||||||
slirp |
|

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
libslirp |
| ||||||||||||||||||||||||||||
qemu |
| ||||||||||||||||||||||||||||
qemu-kvm |
| ||||||||||||||||||||||||||||
slirp |
|
Common Weakness Enumeration
References