Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-29130

Опубликовано: 26 нояб. 2020
Источник: redhat
CVSS3: 2.5

Описание

slirp.c in libslirp through 4.3.1 has a buffer over-read because it tries to read a certain amount of header data even if that exceeds the total packet length.

An out-of-bounds access issue was found in the SLiRP user networking implementation of QEMU. It could occur while processing ARP/NCSI packets, if the packet length was shorter than required to accommodate respective protocol headers and payload. A privileged guest user may use this flaw to potentially leak host information bytes.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5kvmOut of support scope
Red Hat Enterprise Linux 5xenNot affected
Red Hat Enterprise Linux 6qemu-kvmOut of support scope
Red Hat Enterprise Linux 7qemu-kvmFix deferred
Red Hat Enterprise Linux 7qemu-kvm-maFix deferred
Red Hat Enterprise Linux 7qemu-kvm-rhevFix deferred
Red Hat Enterprise Linux 8 Advanced Virtualizationvirt:8.3/qemu-kvmAffected
Red Hat Enterprise Linux 8virt-develFixedRHSA-2021:176218.05.2021
Red Hat Enterprise Linux 8virtFixedRHSA-2021:176218.05.2021

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=1902231QEMU: slirp: out-of-bounds access while processing ARP/NCSI packets

2.5 Low

CVSS3

Связанные уязвимости

CVSS3: 4.3
ubuntu
больше 4 лет назад

slirp.c in libslirp through 4.3.1 has a buffer over-read because it tries to read a certain amount of header data even if that exceeds the total packet length.

CVSS3: 4.3
nvd
больше 4 лет назад

slirp.c in libslirp through 4.3.1 has a buffer over-read because it tries to read a certain amount of header data even if that exceeds the total packet length.

CVSS3: 4.3
debian
больше 4 лет назад

slirp.c in libslirp through 4.3.1 has a buffer over-read because it tr ...

suse-cvrf
около 3 лет назад

Security update for slirp4netns

suse-cvrf
около 3 лет назад

Security update for slirp4netns

2.5 Low

CVSS3