CVE-2020-7211: Path Traversal
Published Jan 21, 2020
·Updated
tftp.c in libslirp 4.1.0, as used in QEMU 4.2.0, does not prevent ..\ directory traversal on Windows.
Affected Software
6 affected components
Libslirp Project Libslirp=4.1.0
Microsoft Windows
Qemu Qemu=4.2.0
All of the following
Libslirp Project Libslirp=4.1.0
Microsoft Windows
debian/libslirp<=4.4.0-1+deb11u2, <=4.7.0-1, <=4.8.0-1, <=4.9.3-1
Remediation
Event History
Jan 21, 2020
CVE Published
via MITRE·04:12 PM
Data Sourced
via MITRE·04:12 PM
Description
Data Sourced
via NVD·05:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Jun 29, 2026
Data Sourced
via Debian·03:42 AM
DescriptionAffected Software
Frequently Asked Questions
1
What is CVE-2020-7211?
CVE-2020-7211 is a vulnerability in the libslirp library, as used in QEMU, that allows directory traversal on Windows systems.
2
What is the severity of CVE-2020-7211?
The severity of CVE-2020-7211 is rated as high, with a severity value of 7.5.
3
How does CVE-2020-7211 affect Windows systems?
CVE-2020-7211 allows directory traversal on Windows systems, potentially enabling attackers to access files outside of the intended directory.
4
What is the affected version of libslirp in CVE-2020-7211?
The affected version of libslirp in CVE-2020-7211 is 4.1.0, as used in QEMU 4.2.0.
5
How can the CVE-2020-7211 vulnerability be fixed?
To fix the CVE-2020-7211 vulnerability, it is recommended to update libslirp to version 4.4.0-1+deb11u2 or 4.7.0-1 or later.