CVE-2020-8608
MEDIUM5.6EPSS 1.5%qemu - security update
發布日:2020/2/6修改日:2026/4/28
描述
In libslirp 4.1.0, as used in QEMU 4.2.0, tcp_subr.c misuses snprintf return values, leading to a buffer overflow in later code.
受影響套件(6)
- Debian/libslirpfrom 0, < 4.2.0-1
- Debian/qemufrom 0, < 1:4.1-2
- Debian/qemufrom 0, < 1:3.1+dfsg-8+deb10u7
- Debian/slirpfrom 0, < 1:1.0.17-11
- Debian/slirpfrom 0, < 1:1.0.17-7+deb8u2
- Debian/slirp4netnsfrom 0, < 1.0.1-1
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM5.6 | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L |