Note:
This project will be discontinued after December 13, 2021. [more]
2020-01-21
tftp.c in libslirp 4.1.0, as used in QEMU 4.2.0, does not prevent ..\ directory traversal on Windows.
Products | Libslirp, Qemu |
Type | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) |
First patch | - None (likely due to unavailable code) |
Links |
• https://gitlab.freedesktop.org/slirp/libslirp/commit/14ec36e107a8c9af7d0a80c3571fe39b291ff1d4
• http://www.openwall.com/lists/oss-security/2020/01/17/2 • https://security-tracker.debian.org/tracker/CVE-2020-7211 |