VDB
DEBIAN-CVE-2020-8608
DEBIAN-CVE-2020-8608
PUBLISHED
CVSS 5.599999904632568 MEDIUM
In libslirp 4.1.0, as used in QEMU 4.2.0, tcp_subr.c misuses snprintf return values, leading to a buffer overflow in later code.
Risk Scores
CVSS 3.1
5.599999904632568
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Debian:14 | qemu | 0, 0, 0 |
| Debian:11 | qemu | 0, 0, 0 |
| Debian:14 | libslirp | 0, 0, 0 |
| Debian:12 | slirp | 0, 0, 0 |
| Debian:12 | qemu | 0, 0, 0 |
| Debian:12 | libslirp | 0, 0, 0 |
| Debian:11 | libslirp | 0, 0, 0 |
| Debian:13 | slirp4netns | 0, 0, 0 |
| Debian:13 | qemu | 0, 0, 0 |
| Debian:12 | slirp4netns | 0, 0, 0 |
| Debian:14 | slirp4netns | 0, 0, 0 |
| Debian:14 | slirp | 0, 0, 0 |
| Debian:13 | slirp | 0, 0, 0 |
| Debian:11 | slirp4netns | 0, 0, 0 |
| Debian:11 | slirp | 0, 0, 0 |
| Debian:13 | libslirp | 0, 0, 0 |
Timeline
- Feb 6, 2020 CVE Published
- Apr 28, 2026 CVE Updated