CVE-2021-3592 log
Source |
|
Severity | Medium |
Remote | No |
Type | Information disclosure |
Description | An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU before version 4.6.0. The flaw exists in the bootp_input() function and could occur while processing a UDP packet that is smaller than the size of the 'bootp_t' structure. A malicious guest could use this flaw to leak 10 bytes of uninitialized heap memory from the host. |
Group | Package | Affected | Fixed | Severity | Status | Ticket |
---|---|---|---|---|---|---|
AVG-2073 | libslirp | 4.5.0-1 | 4.6.0-1 | Medium | Fixed |
Date | Advisory | Group | Package | Severity | Type |
---|---|---|---|---|---|
22 Jun 2021 | ASA-202106-49 | AVG-2073 | libslirp | Medium | information disclosure |