Path traversal in libslirp - CVE-2020-7211

 

Path traversal in libslirp - CVE-2020-7211

Published: February 19, 2020 / Updated: April 28, 2020


Vulnerability identifier: #VU25457
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-7211
CWE-ID: CWE-22
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows an  attacker to perform directory traversal attacks.

The vulnerability exists due to input validation error when processing directory traversal sequences within tftp.c in libslirp. A remote attacker can send a specially crafted TFPT request and read arbitrary files on the Windows system.


Affected software

libslirp
skopeo (Red Hat package)
slirp4netns (Red Hat package)
ignition (Red Hat package)
cri-o (Red Hat package)
openshift (Red Hat package)
openshift-clients (Red Hat package)
openshift-ansible (Red Hat package)
machine-config-daemon (Red Hat package)
atomic-openshift-service-idler (Red Hat package)
atomic-enterprise-service-catalog (Red Hat package)
openshift-kuryr (Red Hat package)
openstack-ironic-python-agent (Red Hat package)
rhosp-release (Red Hat package)
Red Hat OpenShift Container Platform

How to mitigate CVE-2020-7211

Install update from vendor's website.

libslirp - update to 4.2.0
skopeo (Red Hat package) - update to 0.1.40-3.rhaos.el8
slirp4netns (Red Hat package) - update to 0.4.2-3.git21fdece.el8
ignition (Red Hat package) - update to 0.34.0-2.rhaos4.3.git92f874c.el8
cri-o (Red Hat package) - addressed in versions 1.16.2-13.dev.rhaos4.3.gita83f883.el7, 1.16.2-15.dev.rhaos4.3.gita83f883.el8
Red Hat OpenShift Container Platform - update to 4.3.1
openshift (Red Hat package) - addressed in versions 4.3.1-202001310552.git.0.331f390.el7, 4.3.1-202001310552.git.0.331f390.el8
openshift-clients (Red Hat package) - addressed in versions 4.3.1-202001310552.git.1.075d46a.el7, 4.3.1-202001310552.git.1.075d46a.el8
openshift-ansible (Red Hat package) - update to 4.3.1-202001310552.git.174.dcdb91b.el7
machine-config-daemon (Red Hat package) - update to 4.3.1-202002031701.git.1.0ad9b3b.el8
atomic-openshift-service-idler (Red Hat package) - update to 4.3.1-202002031701.git.1.a23cda8.el7
atomic-enterprise-service-catalog (Red Hat package) - update to 4.3.1-202002031701.git.1.095aaf2.el7
openshift-kuryr (Red Hat package) - update to 4.3.1-202002031701.git.1.cfa4a05.el8
openstack-ironic-python-agent (Red Hat package) - update to 5.0.1-0.20200123140814.025b790.el8ost
rhosp-release (Red Hat package) - update to 16.0.0-1.el8ost

External References

Related Security Bulletins