USN-4632-1
Dashboard / Vulnerabilities / USN-4632-1
USN-4632-1
Summary: slirp vulnerabilities
Details: It was discovered that the SLiRP networking implementation of the QEMU emulator did not properly manage memory under certain circumstances. An attacker could use this to cause a heap-based buffer overflow or other out- of-bounds access, which can lead to a denial of service (application crash) or potentially execute arbitrary code. (CVE-2020-7039) It was discovered that the SLiRP networking implementation of the QEMU emulator misuses snprintf return values. An attacker could use this to cause a denial of service (application crash) or potentially execute arbitrary code. (CVE-2020-8608)
References: https://ubuntu.com/security/notices/USN-4632-1, https://ubuntu.com/security/CVE-2020-7039, https://ubuntu.com/security/CVE-2020-8608
Affected packages
Package
Name: slirp
Purl: pkg:deb/ubuntu/slirp@1:1.0.17-8ubuntu16.04.1?arch=source&distro=xenial
Affected ranges
Type: ECOSYSTEM
Events:
