ID:4782 - Exploit for Use-after-free in libslirp - CVE-2020-1983

 
Main Vulnerability Database Exploits ID:4782 - Exploit for Use-after-free in libslirp - CVE-2020-1983

ID:4782 - Exploit for Use-after-free in libslirp - CVE-2020-1983

Published: November 3, 2020


Vulnerability identifier: #VU27389
Vulnerability risk: Medium
CVE-ID: CVE-2020-1983
CWE-ID: CWE-416
Exploitation vector: Remote access
Vulnerable software:
libslirp

Link to public exploit:


Vulnerability description

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a use-after-free error when processing packets within the ip_reass() function in ip_input.c in libslirp. A remote attacker can send a specially crafted packet to the application, trigger a use-after-free error and crash it.


Remediation

Install updates from vendor's website.