Lucene search

K
ubuntucveUbuntu.comUB:CVE-2021-3593
HistoryJun 15, 2021 - 12:00 a.m.

CVE-2021-3593

2021-06-1500:00:00
ubuntu.com
ubuntu.com
11
slirp networking
out-of-bounds read
indirect host memory disclosure
libslirp
cve-2021-3593

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

CVSS3

3.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N

EPSS

0.001

Percentile

16.3%

An invalid pointer initialization issue was found in the SLiRP networking
implementation of QEMU. The flaw exists in the udp6_input() function and
could occur while processing a udp packet that is smaller than the size of
the ‘udphdr’ structure. This issue may lead to out-of-bounds read access or
indirect host memory disclosure to the guest. The highest threat from this
vulnerability is to data confidentiality. This flaw affects libslirp
versions prior to 4.6.0.

Bugs

Rows per page:
1-10 of 121

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

CVSS3

3.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N

EPSS

0.001

Percentile

16.3%