Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2020-10756

Опубликовано: 09 июл. 2020
Источник: debian

Описание

An out-of-bounds read vulnerability was found in the SLiRP networking implementation of the QEMU emulator. This flaw occurs in the icmp6_send_echoreply() routine while replying to an ICMP echo request, also known as ping. This flaw allows a malicious guest to leak the contents of the host memory, resulting in possible information disclosure. This flaw affects versions of libslirp before 4.3.1.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libslirpfixed4.3.1-1package
qemufixed1:4.1-2package
slirp4netnsfixed1.0.1-1package
slirp4netnsno-dsabusterpackage

Примечания

  • qemu 1:4.1-2 switched to system libslirp, marking that version as fixed.

  • slirp4netns 1.0.1-1 switched to system libslirp, marking that version as fixed.

  • https://bugzilla.redhat.com/show_bug.cgi?id=1835986#c11

  • https://github.com/rootless-containers/slirp4netns/security/advisories/GHSA-96c5-v27g-58vf

Связанные уязвимости

CVSS3: 6.5
ubuntu
почти 5 лет назад

An out-of-bounds read vulnerability was found in the SLiRP networking implementation of the QEMU emulator. This flaw occurs in the icmp6_send_echoreply() routine while replying to an ICMP echo request, also known as ping. This flaw allows a malicious guest to leak the contents of the host memory, resulting in possible information disclosure. This flaw affects versions of libslirp before 4.3.1.

CVSS3: 6.5
redhat
около 5 лет назад

An out-of-bounds read vulnerability was found in the SLiRP networking implementation of the QEMU emulator. This flaw occurs in the icmp6_send_echoreply() routine while replying to an ICMP echo request, also known as ping. This flaw allows a malicious guest to leak the contents of the host memory, resulting in possible information disclosure. This flaw affects versions of libslirp before 4.3.1.

CVSS3: 6.5
nvd
почти 5 лет назад

An out-of-bounds read vulnerability was found in the SLiRP networking implementation of the QEMU emulator. This flaw occurs in the icmp6_send_echoreply() routine while replying to an ICMP echo request, also known as ping. This flaw allows a malicious guest to leak the contents of the host memory, resulting in possible information disclosure. This flaw affects versions of libslirp before 4.3.1.

suse-cvrf
почти 5 лет назад

Security update for slirp4netns

suse-cvrf
почти 5 лет назад

Security update for slirp4netns

Уязвимость CVE-2020-10756