Описание
Security update for slirp4netns
This update for slirp4netns fixes the following issues:
- Update to 0.4.7 (bsc#1172380)
- libslirp: update to v4.3.1 (Fix CVE-2020-10756)
- Fix config_from_options() to correctly enable ipv6
This update was imported from the SUSE:SLE-15-SP1:Update update project.
Список пакетов
openSUSE Leap 15.1
slirp4netns-0.4.7-lp151.2.12.1
Ссылки
- E-Mail link for openSUSE-SU-2020:0987-1
- SUSE Security Ratings
- SUSE Bug 1172380
- SUSE CVE CVE-2020-10756 page
Описание
An out-of-bounds read vulnerability was found in the SLiRP networking implementation of the QEMU emulator. This flaw occurs in the icmp6_send_echoreply() routine while replying to an ICMP echo request, also known as ping. This flaw allows a malicious guest to leak the contents of the host memory, resulting in possible information disclosure. This flaw affects versions of libslirp before 4.3.1.
Затронутые продукты
openSUSE Leap 15.1:slirp4netns-0.4.7-lp151.2.12.1
Ссылки
- CVE-2020-10756
- SUSE Bug 1172380
- SUSE Bug 1184743