CVE-2020-7039
16.01.2020, 23:15
tcp_emu in tcp_subr.c in libslirp 4.1.0, as used in QEMU 4.2.0, mismanages memory, as demonstrated by IRC DCC commands in EMU_IRC. This can cause a heap-based buffer overflow or other out-of-bounds access which can lead to a DoS or potential execute arbitrary code.Enginsight
| Vendor | Product | Version |
|---|---|---|
| libslirp_project | libslirp | 4.1.0 |
| qemu | qemu | 4.2.0 |
| debian | debian_linux | 8.0 |
| debian | debian_linux | 9.0 |
| opensuse | leap | 15.1 |
𝑥
= Vulnerable software versions
Debian Releases
Debian Product | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|
| libslirp |
| ||||||||||
| qemu |
| ||||||||||
| slirp |
|
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| libslirp |
| ||||||||||||||||||||||||||||
| qemu |
| ||||||||||||||||||||||||||||
| qemu-kvm |
| ||||||||||||||||||||||||||||
| slirp |
|
Common Weakness Enumeration
References