Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2020-29129

Опубликовано: 26 нояб. 2020
Источник: debian

Описание

ncsi.c in libslirp through 4.3.1 has a buffer over-read because it tries to read a certain amount of header data even if that exceeds the total packet length.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libslirpfixed4.4.0-1package
qemufixed1:4.1-2package
qemunot-affectedstretchpackage

Примечания

  • https://gitlab.freedesktop.org/slirp/libslirp/-/commit/2e1dcbc0c2af64fcb17009eaf2ceedd81be2b27f (v4.4.0)

  • qemu 1:4.1-2 switched to system libslirp, marking that version as fixed.

  • NC-SI introduced in: https://git.qemu.org/?p=qemu.git;a=commit;h=47bb83cad45eb7ce194a8ffd18f73c98edb46aec (QEMU v2.10)

  • https://github.com/rootless-containers/slirp4netns/security/advisories/GHSA-2j37-w439-87q3

Связанные уязвимости

CVSS3: 4.3
ubuntu
больше 4 лет назад

ncsi.c in libslirp through 4.3.1 has a buffer over-read because it tries to read a certain amount of header data even if that exceeds the total packet length.

CVSS3: 2.5
redhat
больше 4 лет назад

ncsi.c in libslirp through 4.3.1 has a buffer over-read because it tries to read a certain amount of header data even if that exceeds the total packet length.

CVSS3: 4.3
nvd
больше 4 лет назад

ncsi.c in libslirp through 4.3.1 has a buffer over-read because it tries to read a certain amount of header data even if that exceeds the total packet length.

CVSS3: 4.3
fstec
больше 4 лет назад

Уязвимость компонента src/ncsi.c эмулятора TCP-IP Libslirp, позволяющая нарушителю получить доступ к конфиденциальным данным

suse-cvrf
около 4 лет назад

Security update for qemu