Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-29129

Опубликовано: 26 нояб. 2020
Источник: redhat
CVSS3: 2.5
EPSS Низкий

Описание

ncsi.c in libslirp through 4.3.1 has a buffer over-read because it tries to read a certain amount of header data even if that exceeds the total packet length.

An out-of-bounds access issue was found in the SLiRP user networking implementation of QEMU. It could occur while processing ARP/NCSI packets, if the packet length was shorter than required to accommodate respective protocol headers and payload. A privileged guest user may use this flaw to potentially leak host information bytes.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5kvmOut of support scope
Red Hat Enterprise Linux 5xenNot affected
Red Hat Enterprise Linux 6qemu-kvmOut of support scope
Red Hat Enterprise Linux 7qemu-kvmFix deferred
Red Hat Enterprise Linux 7qemu-kvm-maFix deferred
Red Hat Enterprise Linux 7qemu-kvm-rhevFix deferred
Red Hat Enterprise Linux 8 Advanced Virtualizationvirt:8.3/qemu-kvmAffected
Red Hat Enterprise Linux 8virt-develFixedRHSA-2021:176218.05.2021
Red Hat Enterprise Linux 8virtFixedRHSA-2021:176218.05.2021

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=1902231QEMU: slirp: out-of-bounds access while processing ARP/NCSI packets

EPSS

Процентиль: 45%
0.0022
Низкий

2.5 Low

CVSS3

Связанные уязвимости

CVSS3: 4.3
ubuntu
больше 4 лет назад

ncsi.c in libslirp through 4.3.1 has a buffer over-read because it tries to read a certain amount of header data even if that exceeds the total packet length.

CVSS3: 4.3
nvd
больше 4 лет назад

ncsi.c in libslirp through 4.3.1 has a buffer over-read because it tries to read a certain amount of header data even if that exceeds the total packet length.

CVSS3: 4.3
debian
больше 4 лет назад

ncsi.c in libslirp through 4.3.1 has a buffer over-read because it tri ...

CVSS3: 4.3
fstec
больше 4 лет назад

Уязвимость компонента src/ncsi.c эмулятора TCP-IP Libslirp, позволяющая нарушителю получить доступ к конфиденциальным данным

suse-cvrf
около 4 лет назад

Security update for qemu

EPSS

Процентиль: 45%
0.0022
Низкий

2.5 Low

CVSS3