PT-2019-3474 · Oracle+8 · Virtualbox+9

Stefanha

·

Published

2019-07-28

·

Updated

2024-06-15

·

CVE-2019-14378

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions libslirp version 4.0.0
Description The issue is related to a heap-based buffer overflow in the ip reass function of the libslirp library, which can be exploited by a remote attacker to gain unauthorized access to information, cause a denial of service, or impact the availability of information. This problem affects QEMU, systems using KVM in Usermode, Virtualbox, and applications that use the libSLIRP network stack.
Recommendations For libslirp version 4.0.0, consider disabling the ip reass function in the ip input.c file as a temporary workaround until a patch is available. Restrict access to the vulnerable libslirp library to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Handling of Exceptional Conditions

Buffer Overflow

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2019:3403
ALSA-2019:3494
BDU:2019-03648
CESA-2019_3403
CESA-2019_3494
CESA-2020_0366
CESA-2020_0775
CVE-2019-14378
DLA-1927-1
DSA-4506-1
DSA-4512-1
OPENSUSE-SU-2019:2041-1
OPENSUSE-SU-2019:2059-1
OPENSUSE-SU-2019:2510-1
OPENSUSE-SU-2019_2041-1
OPENSUSE-SU-2019_2059-1
OPENSUSE-SU-2019_2510-1
OPENSUSE-SU-2024:11287-1
RHSA-2019:3179
RHSA-2019:3403
RHSA-2019:3494
RHSA-2019:3742
RHSA-2019:3787
RHSA-2019:3968
RHSA-2019:4344
RHSA-2019_3403
RHSA-2019_3494
RHSA-2019_3968
RHSA-2020:0366
RHSA-2020:0775
RHSA-2020:0889
RHSA-2020:1216
RHSA-2020:2065
RHSA-2020:2126
RHSA-2020:2342
RHSA-2020_0366
RHSA-2020_0775
RLSA-2019:3403
RLSA-2019:3494
SUSE-SU-2019:14151-1
SUSE-SU-2019:14199-1
SUSE-SU-2019:14201-1
SUSE-SU-2019:2157-1
SUSE-SU-2019:2192-1
SUSE-SU-2019:2221-1
SUSE-SU-2019:2246-1
SUSE-SU-2019:2353-1
SUSE-SU-2019:2753-1
SUSE-SU-2019:2769-1
SUSE-SU-2019:2783-1
SUSE-SU-2019:2955-1
SUSE-SU-2019_14151-1
SUSE-SU-2019_14199-1
SUSE-SU-2020:0388-1
USN-4191-1
USN-4191-2

Affected Products

Almalinux
Centos
Kvm
Qemu
Red Hat
Rocky Linux
Suse
Ubuntu
Virtualbox
Libslirp