ALT-PU-2020-3501-1
Closed vulnerabilities
Published: 2020-11-26
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2020-29129
ncsi.c in libslirp through 4.3.1 has a buffer over-read because it tries to read a certain amount of header data even if that exceeds the total packet length.
Severity: MEDIUM (4.3)
Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
References:
- [oss-security] 20201127 CVE-2020-29129 CVE-2020-29130 QEMU: slirp: out-of-bounds access while processing ARP/NCSI packets
- [oss-security] 20201127 CVE-2020-29129 CVE-2020-29130 QEMU: slirp: out-of-bounds access while processing ARP/NCSI packets
- [debian-lts-announce] 20220905 [SECURITY] [DLA 3099-1] qemu security update
- [debian-lts-announce] 20220905 [SECURITY] [DLA 3099-1] qemu security update
- FEDORA-2020-331e1318dd
- FEDORA-2020-331e1318dd
- FEDORA-2020-77f93f41be
- FEDORA-2020-77f93f41be
- https://lists.freedesktop.org/archives/slirp/2020-November/000115.html
- https://lists.freedesktop.org/archives/slirp/2020-November/000115.html
Published: 2020-11-26
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2020-29130
slirp.c in libslirp through 4.3.1 has a buffer over-read because it tries to read a certain amount of header data even if that exceeds the total packet length.
Severity: MEDIUM (4.3)
Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
References:
- [oss-security] 20201127 CVE-2020-29129 CVE-2020-29130 QEMU: slirp: out-of-bounds access while processing ARP/NCSI packets
- [oss-security] 20201127 CVE-2020-29129 CVE-2020-29130 QEMU: slirp: out-of-bounds access while processing ARP/NCSI packets
- [debian-lts-announce] 20210218 [SECURITY] [DLA 2560-1] qemu security update
- [debian-lts-announce] 20210218 [SECURITY] [DLA 2560-1] qemu security update
- [debian-lts-announce] 20230314 [SECURITY] [DLA 3362-1] qemu security update
- [debian-lts-announce] 20230314 [SECURITY] [DLA 3362-1] qemu security update
- FEDORA-2020-331e1318dd
- FEDORA-2020-331e1318dd
- FEDORA-2020-77f93f41be
- FEDORA-2020-77f93f41be
- https://lists.freedesktop.org/archives/slirp/2020-November/000115.html
- https://lists.freedesktop.org/archives/slirp/2020-November/000115.html