CVE-2020-7039Out-of-bounds Write in Project Libslirp

Severity
5.6MEDIUMNVD
EPSS
0.8%
top 25.40%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 16
Latest updateNov 8

Description

tcp_emu in tcp_subr.c in libslirp 4.1.0, as used in QEMU 4.2.0, mismanages memory, as demonstrated by IRC DCC commands in EMU_IRC. This can cause a heap-based buffer overflow or other out-of-bounds access which can lead to a DoS or potential execute arbitrary code.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:LExploitability: 2.2 | Impact: 3.4

Affected Packages5 packages

Debianqemu/qemu< 1:4.1-2+3
Debianlibslirp_project/libslirp< 4.1.0-2+3
NVDqemu/qemu4.2.0
NVDopensuse/leap15.1

Also affects: Debian Linux 8.0, 9.0

Patches

🔴Vulnerability Details

5
GHSA
GHSA-fr8m-vw66-8v9r: tcp_emu in tcp_subr2022-05-24
OSV
slirp vulnerabilities2020-11-12
OSV
qemu vulnerabilities2020-02-18
OSV
CVE-2020-7039: tcp_emu in tcp_subr2020-01-16
CVEList
CVE-2020-7039: tcp_emu in tcp_subr2020-01-16

📋Vendor Advisories

6
Ubuntu
QEMU vulnerabilities2024-11-08
Ubuntu
SLiRP vulnerabilities2020-11-12
Ubuntu
QEMU vulnerabilities2020-02-18
Microsoft
tcp_emu in tcp_subr.c in libslirp 4.1.0 as used in QEMU 4.2.0 mismanages memory as demonstrated by IRC DCC commands in EMU_IRC. This can cause a heap-based buffer overflow or other out-of-bounds acces2020-01-14
Red Hat
QEMU: slirp: OOB buffer access while emulating tcp protocols in tcp_emu()2020-01-07

💬Community

2
Bugzilla
CVE-2020-7039 QEMU: slirp: OOB buffer access while emulating tcp protocols in tcp_emu()2020-01-16
Bugzilla
CVE-2020-7039 qemu: slirp: OOB buffer access while emulating tcp protocols in tcp_emu() [fedora-all]2020-01-16
CVE-2020-7039 — Out-of-bounds Write in Project Libslirp | cvebase