#VU25456 Buffer overflow in libslirp - CVE-2020-8608
Published: February 19, 2020 / Updated: April 28, 2020
Vulnerability identifier: #VU25456
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2020-8608
CWE-ID: CWE-119
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerable software:
libslirp
libslirp
Software vendor:
Freedesktop.org
Freedesktop.org
Description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a boundary error within tcp_subr.c file in libslirp. A local user can pass specially crafted data to the application that is using the affected version of library, trigger memory corruption and execute arbitrary code on the system.
Remediation
Install update from vendor's website.