CVE-2020-10756

Name
CVE-2020-10756
Description
An out-of-bounds read vulnerability was found in the SLiRP networking implementation of the QEMU emulator. This flaw occurs in the icmp6_send_echoreply() routine while replying to an ICMP echo request, also known as ping. This flaw allows a malicious guest to leak the contents of the host memory, resulting in possible information disclosure. This flaw affects versions of libslirp before 4.3.1.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
Issue Tracking https://bugzilla.redhat.com/show_bug.cgi?id=1835986
Mailing List https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JYTZ32P67PZER6P7TW6FQK3SZRKQLVEI/
Mailing List http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00035.html
Mailing List http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00040.html
Mailing List https://www.debian.org/security/2020/dsa-4728
Mailing List https://lists.debian.org/debian-lts-announce/2020/07/msg00020.html
Third Party Advisory https://usn.ubuntu.com/4437-1/
Third Party Advisory https://www.zerodayinitiative.com/advisories/ZDI-20-1005/
UBUNTU https://usn.ubuntu.com/4467-1/
CONFIRM https://security.netapp.com/advisory/ntap-20201001-0001/

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:libslirp_project:libslirp:*:*:*:*:*:*:*:* libslirp >= None < 4.3.1

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
libslirp edge-community 4.3.1-r0 None fixed
libslirp edge-community 4.3.0-r0 None possibly vulnerable
libslirp 3.22-community 4.3.1-r0 None fixed
libslirp 3.22-community 4.3.0-r0 None possibly vulnerable
libslirp 3.21-community 4.3.1-r0 None fixed
libslirp 3.20-community 4.3.1-r0 None fixed
libslirp 3.19-community 4.3.1-r0 None fixed
libslirp 3.18-community 4.3.1-r0 None fixed
libslirp 3.17-community 4.3.1-r0 None fixed