Source: libslirp
Version: 4.4.0-1
Severity: important
Tags: security upstream
X-Debbugs-Cc: car...@debian.org, Debian Security Team <t...@security.debian.org>

Hi,

The following vulnerability was published for libslirp.

CVE-2021-3593[0]:
| An invalid pointer initialization issue was found in the SLiRP
| networking implementation of QEMU. The flaw exists in the udp6_input()
| function and could occur while processing a udp packet that is smaller
| than the size of the 'udphdr' structure. This issue may lead to out-
| of-bounds read access or indirect host memory disclosure to the guest.
| The highest threat from this vulnerability is to data confidentiality.
| This flaw affects libslirp versions prior to 4.6.0.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2021-3593
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3593

Regards,
Salvatore

Reply via email to