Vulnerabilities > CVE-2019-14378 - Improper Handling of Exceptional Conditions vulnerability in Libslirp Project Libslirp 4.0.0
Attack vector
NETWORK Attack complexity
LOW Privileges required
LOW Confidentiality impact
HIGH Integrity impact
HIGH Availability impact
HIGH Summary
ip_reass in ip_input.c in libslirp 4.0.0 has a heap-based buffer overflow via a large packet because it mishandles a case involving the first fragment.
Vulnerable Configurations
Part | Description | Count |
Application | 1 |
Common Weakness Enumeration (CWE)
id | EDB-ID:47320 |
last seen | 2019-08-30 |
modified | 2019-08-20 |
published | 2019-08-20 |
reporter | Exploit-DB |
source | |
title | QEMU - Denial of Service |
NASL family CentOS Local Security Checks
NASL id CENTOS_RHSA-2020-0366.NASL
description An update for qemu-kvm is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Kernel-based Virtual Machine (KVM) is a full virtualization solution for Linux on a variety of architectures. The qemu-kvm packages provide the user-space component for running virtual machines that use KVM. Security Fix(es) : * hw: TSX Transaction Asynchronous Abort (TAA) (CVE-2019-11135) * QEMU: slirp: heap buffer overflow during packet reassembly (CVE-2019-14378) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Bug Fix(es) : * [Intel 7.8 Bug] [KVM][CLX] CPUID_7_0_EDX_ARCH_CAPABILITIES is not enabled in VM qemu-kvm (BZ#1730606) Enhancement(s) : * [Intel 7.8 FEAT] MDS_NO exposure to guest - qemu-kvm (BZ#1755333)
last seen 2020-06-01
modified 2020-06-02
plugin id 133507
published 2020-02-06
reporter This script is Copyright (C) 2020 and is owned by Tenable, Inc. or an Affiliate thereof.
source
title CentOS 7 : qemu-kvm (CESA-2020:0366) data source | |
id | PACKETSTORM:154269 |
last seen | 2019-08-31 |
published | 2019-08-30 |
reporter | vishnudevtj |
source | |
title | QEMU Denial Of Service |
advisories |
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
rpms |