Back to search
CVE-2020-7039
Published: Jan 16, 2020
Modified: Aug 4, 2024
PUBLISHED
Description
tcp_emu in tcp_subr.c in libslirp 4.1.0, as used in QEMU 4.2.0, mismanages memory, as demonstrated by IRC DCC commands in EMU_IRC. This can cause a heap-based buffer overflow or other out-of-bounds access which can lead to a DoS or potential execute arbitrary code.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
http://www.openwall.com/lists/oss-security/2020/01/16/2
x_refsource_CONFIRM
[debian-lts-announce] 20200126 [SECURITY] [DLA 2076-1] slirp security update
mailing-list
x_refsource_MLIST
[debian-lts-announce] 20200131 [SECURITY] [DLA 2090-1] qemu security update
mailing-list
x_refsource_MLIST
20200203 [SECURITY] [DSA 4616-1] qemu security update
mailing-list
x_refsource_BUGTRAQ
DSA-4616
vendor-advisory
x_refsource_DEBIAN
RHSA-2020:0348
vendor-advisory
x_refsource_REDHAT
USN-4283-1
vendor-advisory
x_refsource_UBUNTU
RHSA-2020:0775
vendor-advisory
x_refsource_REDHAT
openSUSE-SU-2020:0468
vendor-advisory
x_refsource_SUSE
GLSA-202005-02
vendor-advisory
x_refsource_GENTOO
[debian-lts-announce] 20210209 [SECURITY] [DLA 2551-1] slirp security update
mailing-list
x_refsource_MLIST
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now