Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 731990 (CVE-2020-10756) - [Tracker]: libslirp: Information disclosure via crafted ipv6 packets (CVE-2020-10756)
Summary: [Tracker]: libslirp: Information disclosure via crafted ipv6 packets (CVE-202...
Status: RESOLVED FIXED
Alias: CVE-2020-10756
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL: https://bugzilla.redhat.com/show_bug....
Whiteboard:
Keywords: Tracker
Depends on: 731988 731992
Blocks:
  Show dependency tree
 
Reported: 2020-07-09 21:46 UTC by John Helmert III
Modified: 2020-08-08 04:30 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description John Helmert III gentoo-dev Security 2020-07-09 21:46:06 UTC
CVE-2020-10756:

An out-of-bounds read vulnerability was found in the SLiRP networking implementation of the QEMU emulator. This flaw occurs in the icmp6_send_echoreply() routine while replying to an ICMP echo request, also known as ping. This flaw allows a malicious guest to leak the contents of the host memory, resulting in possible information disclosure. This flaw affects versions of libslirp before 4.3.1.