Lucene search

K
osvGoogleOSV:USN-4632-1
HistoryNov 12, 2020 - 8:31 p.m.

slirp vulnerabilities

2020-11-1220:31:20
Google
osv.dev
4

8.2 High

AI Score

Confidence

High

0.007 Low

EPSS

Percentile

80.3%

It was discovered that the SLiRP networking implementation of the QEMU
emulator did not properly manage memory under certain circumstances. An
attacker could use this to cause a heap-based buffer overflow or other out-
of-bounds access, which can lead to a denial of service (application crash)
or potentially execute arbitrary code. (CVE-2020-7039)

It was discovered that the SLiRP networking implementation of the QEMU
emulator misuses snprintf return values. An attacker could use this to
cause a denial of service (application crash) or potentially execute
arbitrary code. (CVE-2020-8608)