First published: Tue Jan 21 2020(Updated: )
tftp.c in libslirp 4.1.0, as used in QEMU 4.2.0, does not prevent ..\ directory traversal on Windows.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Libslirp Project Libslirp | =4.1.0 | |
Microsoft Windows | ||
QEMU qemu | =4.2.0 | |
debian/libslirp | <=4.4.0-1+deb11u2<=4.7.0-1<=4.8.0-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-7211 is a vulnerability in the libslirp library, as used in QEMU, that allows directory traversal on Windows systems.
The severity of CVE-2020-7211 is rated as high, with a severity value of 7.5.
CVE-2020-7211 allows directory traversal on Windows systems, potentially enabling attackers to access files outside of the intended directory.
The affected version of libslirp in CVE-2020-7211 is 4.1.0, as used in QEMU 4.2.0.
To fix the CVE-2020-7211 vulnerability, it is recommended to update libslirp to version 4.4.0-1+deb11u2 or 4.7.0-1 or later.