CVE-2020-10756

CVSS v3.1 6.5 (Medium)
65% Progress
CVSS v2.0 2.1 (Low)
21% Progress
EPSS 0.07 % (31th)
0.07% Progress
Affected Products 6
Advisories 25

An out-of-bounds read vulnerability was found in the SLiRP networking implementation of the QEMU emulator. This flaw occurs in the icmp6_send_echoreply() routine while replying to an ICMP echo request, also known as ping. This flaw allows a malicious guest to leak the contents of the host memory, resulting in possible information disclosure. This flaw affects versions of libslirp before 4.3.1.

Weaknesses
CWE-125
Out-of-bounds Read
Related CVEs
CVE Status
PUBLISHED
CNA
Red Hat, Inc.
Published Date
2020-07-09 16:15:13
(4 years ago)
Updated Date
2023-11-07 03:14:20
(10 months ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Libslirp Project Libslirp prior 4.3.1 version cpe:2.3:a:libslirp_project:libslirp < 4.3.1

Configuration #2

    CPE23 From Up To
  Redhat Openstack 13 cpe:2.3:a:redhat:openstack:13
  Redhat Enterprise Linux 7.0 cpe:2.3:o:redhat:enterprise_linux:7.0
  Redhat Enterprise Linux 8.0 cpe:2.3:o:redhat:enterprise_linux:8.0
  Redhat Enterprise Linux 8.0 cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:advanced_virtualization

Configuration #3

    CPE23 From Up To
  Canonical Ubuntu Linux 16.04 cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm
  Canonical Ubuntu Linux 18.04 cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts
  Canonical Ubuntu Linux 20.04 cpe:2.3:o:canonical:ubuntu_linux:20.04:*:*:*:lts

Configuration #4

    CPE23 From Up To
  Debian Linux 9.0 cpe:2.3:o:debian:debian_linux:9.0
  Debian Linux 10.0 cpe:2.3:o:debian:debian_linux:10.0

Configuration #5

    CPE23 From Up To
  Opensuse Leap 15.0 cpe:2.3:o:opensuse:leap:15.0
  Opensuse Leap 15.1 cpe:2.3:o:opensuse:leap:15.1
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...