CVE-2020-7211 (NVD)

2020-01-21

tftp.c in libslirp 4.1.0, as used in QEMU 4.2.0, does not prevent ..\ directory traversal on Windows.

Products Libslirp, Qemu
Type Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
First patch - None (likely due to unavailable code)
Links https://gitlab.freedesktop.org/slirp/libslirp/commit/14ec36e107a8c9af7d0a80c3571fe39b291ff1d4
http://www.openwall.com/lists/oss-security/2020/01/17/2
https://security-tracker.debian.org/tracker/CVE-2020-7211