Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-7039

Опубликовано: 16 янв. 2020
Источник: nvd
CVSS3: 5.6
CVSS2: 6.8
EPSS Низкий

Описание

tcp_emu in tcp_subr.c in libslirp 4.1.0, as used in QEMU 4.2.0, mismanages memory, as demonstrated by IRC DCC commands in EMU_IRC. This can cause a heap-based buffer overflow or other out-of-bounds access which can lead to a DoS or potential execute arbitrary code.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:libslirp_project:libslirp:4.1.0:*:*:*:*:*:*:*
Конфигурация 2

Одно из

cpe:2.3:a:qemu:qemu:4.2.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:*

EPSS

Процентиль: 76%
0.0102
Низкий

5.6 Medium

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-787

Связанные уязвимости

CVSS3: 5.6
ubuntu
больше 5 лет назад

tcp_emu in tcp_subr.c in libslirp 4.1.0, as used in QEMU 4.2.0, mismanages memory, as demonstrated by IRC DCC commands in EMU_IRC. This can cause a heap-based buffer overflow or other out-of-bounds access which can lead to a DoS or potential execute arbitrary code.

CVSS3: 5.6
redhat
больше 5 лет назад

tcp_emu in tcp_subr.c in libslirp 4.1.0, as used in QEMU 4.2.0, mismanages memory, as demonstrated by IRC DCC commands in EMU_IRC. This can cause a heap-based buffer overflow or other out-of-bounds access which can lead to a DoS or potential execute arbitrary code.

CVSS3: 5.6
msrc
больше 4 лет назад

Описание отсутствует

CVSS3: 5.6
debian
больше 5 лет назад

tcp_emu in tcp_subr.c in libslirp 4.1.0, as used in QEMU 4.2.0, misman ...

rocky
около 5 лет назад

Important: container-tools:1.0 security update

EPSS

Процентиль: 76%
0.0102
Низкий

5.6 Medium

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-787