Alpaquita LinuxStreamSecurity Advisory
Search Cve

CVE-2020-10756

Published: August 31, 2023Last modified: August 31, 2023

Description

An out-of-bounds read vulnerability was found in the SLiRP networking implementation of the QEMU emulator. This flaw occurs in the icmp6_send_echoreply() routine while replying to an ICMP echo request, also known as ping. This flaw allows a malicious guest to leak the contents of the host memory, resulting in possible information disclosure. This flaw affects versions of libslirp before 4.3.1.

Severity score breakdown

ParameterValue
Base score6.5
Attack VectorLOCAL
Attack complexityLOW
Privileges requiredLOW
User interactionNONE
ScopeCHANGED
ConfidentialityHIGH
Integrity impactNONE
Availability impactNONE
VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSlibslirpNot affected (4.7.0-r0)
StreamlibslirpNot affected (4.7.0-r0)

References

ON THIS PAGE