#VU25457 Path traversal in libslirp - CVE-2020-7211
Published: February 19, 2020 / Updated: April 28, 2020
libslirp
Freedesktop.org
Description
The vulnerability allows an attacker to perform directory traversal attacks.
The vulnerability exists due to input validation error when processing directory traversal sequences within tftp.c in libslirp. A remote attacker can send a specially crafted TFPT request and read arbitrary files on the Windows system.