[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

[SECURITY] [DLA 2076-1] slirp security update



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Package        : slirp
Version        : 1:1.0.17-7+deb8u1
CVE ID         : CVE-2020-7039
Debian Bug     : 949085


An issue has been found in slirp, a SLIP/PPP emulator using a dial up shell account. Due to bad memory handling in slirp a heap-based buffer overflow or other out-of-bounds access could happen, which can lead to a DoS or potential execute arbitrary code.


For Debian 8 "Jessie", this problem has been fixed in version 1:1.0.17-7+deb8u1.

We recommend that you upgrade your slirp packages.

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS

-----BEGIN PGP SIGNATURE-----

iQKTBAEBCgB9FiEEYgH7/9u94Hgi6ruWlvysDTh7WEcFAl4uB/BfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDYy
MDFGQkZGREJCREUwNzgyMkVBQkI5Njk2RkNBQzBEMzg3QjU4NDcACgkQlvysDTh7
WEe7cw//RKnZI6rGUmJLnJF4sYKR8+CU482LZauTXWO19Ry9n4feteHkm5ffPPZ6
fiIBT6VxDQ2fDzJDGFtfRrtsyMzUHu4mEDXE7JYnI4mSnbi0iEvPASdo+nWCKDp3
AOF+hvNz4JC4rh5EKJGLNuX05wHc6OoAAArSBq7day1vCqYIq3NDSeasYSb8vYer
w3irbpTPe3Wx9hD/qk8Ll7IEZY7u5BcytqqJSywF5qpa6RLv5FEwd7vK5CdQzlgP
keuwNTsiJv5cTftbS3J02eo9PZOEks3D5lCExH2jcP8nWV/xMp4Aql/pEzSI1BN8
lcwdSM5v3m442Iy4RqQxMByNa9rmWVi4hCc/tVTV5qqhOkPe20QzTsAUGpEfhoi6
dT46MZSV2wkuZqIEwwK7gPdR5/0Z83AtgeWZN9T5vB4YENp4XKy/tcgzhifhkavg
D9lypBaImgPPRypP07hW8Ugfd+7tr33sQV6AR46KDNldlgznJlM/vb5P3SHmLTgS
dJxfSZ8pHedigGdTcu1QtOdk4Ps2wtR+qdVnvw0Oqn6egrgu2aCAfSOFjKgYgsND
eCfemFiklX/qBddNr5y1emJUSBO8j6sWjSG+fsv6fkMe3Y8qdYN0mcKrAZF4S3SU
OYiXhobFGMsWuKi+Q/1YVbWYAQX74D3l9Xva3il6eEyvJlfyjuQ=
=hWB9
-----END PGP SIGNATURE-----


Reply to: