CVE-2019-14378
CVE-2019-14378
ip_reass in ip_input.c in libslirp 4.0.0 has a heap-based buffer overflow via a large packet because it mishandles a case involving the first fragment.
Productos afectados
n/a · n/aPoCs públicas encontradas — 2
cve_referencepacketstormsecurity.com/files/154269/QEMU-Denial-Of-Service.htmlno verificadoexploitdbwww.exploit-db.com/exploits/47320no verificado⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.
¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →Referencias
http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-09/msg00008.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-11/msg00034.htmlhttp://packetstormsecurity.com/files/154269/QEMU-Denial-Of-Service.htmlhttps://access.redhat.com/errata/RHSA-2019:3179https://access.redhat.com/errata/RHSA-2019:3403https://access.redhat.com/errata/RHSA-2019:3494https://access.redhat.com/errata/RHSA-2019:3742https://access.redhat.com/errata/RHSA-2019:3787https://access.redhat.com/errata/RHSA-2019:3968https://access.redhat.com/errata/RHSA-2019:4344https://access.redhat.com/errata/RHSA-2020:0366