Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2021-3595

Опубликовано: 15 июн. 2021
Источник: ubuntu
Приоритет: low
CVSS2: 2.1
CVSS3: 3.8

Описание

An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU. The flaw exists in the tftp_input() function and could occur while processing a udp packet that is smaller than the size of the 'tftp_t' structure. This issue may lead to out-of-bounds read access or indirect host memory disclosure to the guest. The highest threat from this vulnerability is to data confidentiality. This flaw affects libslirp versions prior to 4.6.0.

РелизСтатусПримечание
bionic

DNE

devel

released

4.6.1-1
esm-infra-legacy/trusty

DNE

esm-infra/focal

not-affected

4.1.0-2ubuntu2.2
focal

released

4.1.0-2ubuntu2.2
groovy

released

4.3.1-1ubuntu0.1
hirsute

released

4.4.0-1ubuntu0.1
impish

released

4.4.0-1ubuntu0.21.10.1
jammy

released

4.6.1-1
kinetic

released

4.6.1-1

Показывать по

РелизСтатусПримечание
bionic

released

1:2.11+dfsg-1ubuntu7.37
devel

not-affected

uses system libslirp
esm-infra-legacy/trusty

not-affected

code not present
esm-infra/bionic

not-affected

1:2.11+dfsg-1ubuntu7.37
esm-infra/focal

not-affected

uses system libslirp
esm-infra/xenial

not-affected

code not present
focal

not-affected

uses system libslirp
groovy

not-affected

uses system libslirp
hirsute

not-affected

uses system libslirp
impish

not-affected

uses system libslirp

Показывать по

2.1 Low

CVSS2

3.8 Low

CVSS3

Связанные уязвимости

CVSS3: 3.8
redhat
около 4 лет назад

An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU. The flaw exists in the tftp_input() function and could occur while processing a udp packet that is smaller than the size of the 'tftp_t' structure. This issue may lead to out-of-bounds read access or indirect host memory disclosure to the guest. The highest threat from this vulnerability is to data confidentiality. This flaw affects libslirp versions prior to 4.6.0.

CVSS3: 3.8
nvd
около 4 лет назад

An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU. The flaw exists in the tftp_input() function and could occur while processing a udp packet that is smaller than the size of the 'tftp_t' structure. This issue may lead to out-of-bounds read access or indirect host memory disclosure to the guest. The highest threat from this vulnerability is to data confidentiality. This flaw affects libslirp versions prior to 4.6.0.

CVSS3: 3.8
debian
около 4 лет назад

An invalid pointer initialization issue was found in the SLiRP network ...

CVSS3: 3.8
github
около 3 лет назад

An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU. The flaw exists in the tftp_input() function and could occur while processing a udp packet that is smaller than the size of the 'tftp_t' structure. This issue may lead to out-of-bounds read access or indirect host memory disclosure to the guest. The highest threat from this vulnerability is to data confidentiality. This flaw affects libslirp versions prior to 4.6.0.

CVSS3: 3.8
fstec
около 4 лет назад

Уязвимость функции tftp_input() компонента src/tftp.c эмулятора TCP-IP Libslirp, позволяющая нарушителю получить доступ к конфиденциальным данным

2.1 Low

CVSS2

3.8 Low

CVSS3

Уязвимость CVE-2021-3595