SB2020021912 - Multiple vulnerabilities in libslirp
Published: February 19, 2020 Updated: April 28, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 3 secuirty vulnerabilities.
1) Buffer overflow (CVE-ID: CVE-2020-8608)
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a boundary error within tcp_subr.c file in libslirp. A local user can pass specially crafted data to the application that is using the affected version of library, trigger memory corruption and execute arbitrary code on the system.
2) Path traversal (CVE-ID: CVE-2020-7211)
The vulnerability allows an attacker to perform directory traversal attacks.
The vulnerability exists due to input validation error when processing directory traversal sequences within tftp.c in libslirp. A remote attacker can send a specially crafted TFPT request and read arbitrary files on the Windows system.
3) Heap-based buffer overflow (CVE-ID: CVE-2020-7039)
The vulnerability allows an attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error within the tcp_emu() function in tcp_subr.c in libslirp. An attacker can issue specially crafted IRC DCC commands in EMU_IRC, trigger heap-based buffer overflow and execute arbitrary code on the target system.
Remediation
Install update from vendor's website.
References
- https://gitlab.freedesktop.org/slirp/libslirp/-/tags/v4.1.0
- https://gitlab.freedesktop.org/slirp/libslirp/commit/68ccb8021a838066f0951d4b2817eb6b6f10a843
- https://www.openwall.com/lists/oss-security/2020/02/06/2
- http://www.openwall.com/lists/oss-security/2020/01/17/2
- https://gitlab.freedesktop.org/slirp/libslirp/commit/14ec36e107a8c9af7d0a80c3571fe39b291ff1d4
- https://security-tracker.debian.org/tracker/CVE-2020-7211
- http://www.openwall.com/lists/oss-security/2020/01/16/2
- https://gitlab.freedesktop.org/slirp/libslirp/commit/2655fffed7a9e765bcb4701dd876e9dab975f289
- https://gitlab.freedesktop.org/slirp/libslirp/commit/82ebe9c370a0e2970fb5695aa19aa5214a6a1c80
- https://gitlab.freedesktop.org/slirp/libslirp/commit/ce131029d6d4a405cb7d3ac6716d03e58fb4a5d9
- https://lists.debian.org/debian-lts-announce/2020/01/msg00022.html
- https://lists.debian.org/debian-lts-announce/2020/01/msg00036.html
- https://seclists.org/bugtraq/2020/Feb/0
- https://www.debian.org/security/2020/dsa-4616