Buffer overflow in libslirp - CVE-2020-8608

 

Buffer overflow in libslirp - CVE-2020-8608

Published: February 19, 2020 / Updated: April 28, 2020


Vulnerability identifier: #VU25456
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2020-8608
CWE-ID: CWE-119
Exploitation vector: Local access
Exploit availability: No public exploit available
Vendor: Freedesktop.org
Affected software:
libslirp

Detailed vulnerability description

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to a boundary error within tcp_subr.c file in libslirp. A local user can pass specially crafted data to the application that is using the affected version of library, trigger memory corruption and execute arbitrary code on the system.


How to mitigate CVE-2020-8608

Install update from vendor's website.

Sources