UBUNTU-CVE-2020-7039
Dashboard / Vulnerabilities / UBUNTU-CVE-2020-7039
UBUNTU-CVE-2020-7039
Summary:
Details: tcp_emu in tcp_subr.c in libslirp 4.1.0, as used in QEMU 4.2.0, mismanages memory, as demonstrated by IRC DCC commands in EMU_IRC. This can cause a heap-based buffer overflow or other out-of-bounds access which can lead to a DoS or potential execute arbitrary code.
References: https://ubuntu.com/security/CVE-2020-7039, https://www.openwall.com/lists/oss-security/2020/01/16/2, https://ubuntu.com/security/notices/USN-4283-1, https://ubuntu.com/security/notices/USN-4632-1, https://www.cve.org/CVERecord?id=CVE-2020-7039, https://ubuntu.com/security/notices/USN-7094-1
Affected packages
Package
Name: qemu
Purl: pkg:deb/ubuntu/[email protected]+dfsg-2ubuntu1.47+esm4?arch=source&distro=trusty/esm
Affected ranges
Type: ECOSYSTEM
Events:
