#VU25458 Heap-based buffer overflow in libslirp


Published: 2020-02-19 | Updated: 2020-04-28

Vulnerability identifier: #VU25458

Vulnerability risk: Low

CVSSv3.1: 6.8 [CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2020-7039

CWE-ID: CWE-122

Exploitation vector: Local

Exploit availability: No

Vulnerable software:
libslirp
Universal components / Libraries / Libraries used by multiple products

Vendor: Freedesktop.org

Description

The vulnerability allows an attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error within the tcp_emu() function in tcp_subr.c in libslirp. An attacker can issue specially crafted IRC DCC commands in EMU_IRC, trigger heap-based buffer overflow and execute arbitrary code on the target system.

Mitigation
Install update from vendor's website.

Vulnerable software versions

libslirp: 4.1.0


External links
http://www.openwall.com/lists/oss-security/2020/01/16/2
http://gitlab.freedesktop.org/slirp/libslirp/commit/2655fffed7a9e765bcb4701dd876e9dab975f289
http://gitlab.freedesktop.org/slirp/libslirp/commit/82ebe9c370a0e2970fb5695aa19aa5214a6a1c80
http://gitlab.freedesktop.org/slirp/libslirp/commit/ce131029d6d4a405cb7d3ac6716d03e58fb4a5d9
http://lists.debian.org/debian-lts-announce/2020/01/msg00022.html
http://lists.debian.org/debian-lts-announce/2020/01/msg00036.html
http://seclists.org/bugtraq/2020/Feb/0
http://www.debian.org/security/2020/dsa-4616


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.


Latest bulletins with this vulnerability