Login
Newsletter
Werbung

Sicherheit: Denial of Service in libslirp
Aktuelle Meldungen Distributionen
Name: Denial of Service in libslirp
ID: USN-4437-1
Distribution: Ubuntu
Plattformen: Ubuntu 20.04 LTS
Datum: Di, 28. Juli 2020, 07:05
Referenzen: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-10756
Applikationen: libslirp

Originalnachricht

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--===============0672833549759252330==
Content-Type: multipart/signed; micalg=pgp-sha512;
protocol="application/pgp-signature";
boundary="o2A01ob18PkBgqa4W5EnBuFIyyhnlcWdc"

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--o2A01ob18PkBgqa4W5EnBuFIyyhnlcWdc
Content-Type: multipart/mixed;
boundary="GtA9JgBJfw54RsUXEBnrf9V6dC3YNJL2a"

--GtA9JgBJfw54RsUXEBnrf9V6dC3YNJL2a
Content-Type: text/plain; charset=utf-8
Content-Language: en-C
Content-Transfer-Encoding: quoted-printable

==========================================================================
Ubuntu Security Notice USN-4437-1
July 27, 2020

libslirp vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 20.04 LTS

Summary:

libslirp could be made to crash if it received specially crafted network
traffic.

Software Description:
- libslirp: None

Details:

Ziming Zhang and VictorV discovered that libslirp incorrectly handled
replying to certain ICMP echo requests. A remote attacker could possibly
use this issue to cause libslirp to crash, resulting in a denial of
service.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 20.04 LTS:
libslirp0 4.1.0-2ubuntu2.1

After a standard system update you need to reboot your computer to make
all the necessary changes.

References:
https://usn.ubuntu.com/4437-1
CVE-2020-10756

Package Information:
https://launchpad.net/ubuntu/+source/libslirp/4.1.0-2ubuntu2.1


--GtA9JgBJfw54RsUXEBnrf9V6dC3YNJL2a--

--o2A01ob18PkBgqa4W5EnBuFIyyhnlcWdc
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="signature.asc"

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEUMSg3c8x5FLOsZtRZWnYVadEvpMFAl8e90gACgkQZWnYVadE
vpPnJw/9FMYPp6NJVNMKEeJE6JLRQ/ZtOHeVTl2jYm/IXWU/fQ6nHr2qp9HiDPw0
WwYmwkWMIdvlr8t4a5ZponwayxLnuRZHQ9Q1N7Pi2nlUWaUh0FTiamVAxbweMIq2
r7Hz6BSVQ8JQ0fpuKKZ7cJIP889yQP+r0C2oNGr2NhQIgTz5aBSEa6rFGzyom3jp
jX2PeGyFjfWK1wGpVU7RB13Rb5SzjNvBFDjxA6lNSqdXEcsBpvPt0Ubv7Toc8CTH
0hypxXviC1BNpKlhUkQvbpUAhw7Sm+gyNqRbfYFkhi32hIZwkH2JS1wz6qj76T/6
NzF1hUjdLG9jfOuEzUH3EnPlmAmI/cD6IUNkreHYcThq1sG6gT/T9zwu2cVORSGW
y+7Q+dqpBDaanHg8swLqep9k2FZqillTABLmug6pEd9lXDbdxpoW81NfZOWlwzdh
jSMDwkuxFFgRF4/IRp18NntBHleADZLGvYpWJ9IwZAb1Oqjz8TYK4OqFDY1fxu14
ZLpQJhUJSx1taV53JhEZS1hBzTpX5Csfzclvjc9QWBW04nIefztcMtfl9lEv82jw
GvnexYjOEOZ4vccX6FRlFCtgOqLip5/BKg4tWNXSt8iMyFhP8ScDMjVyxUAPIG0m
SgDnD2m3WseCQGDKAlz+jQMp3yBYheuWTY7k5DK6fjcVIVZjayQ=
=H+26
-----END PGP SIGNATURE-----

--o2A01ob18PkBgqa4W5EnBuFIyyhnlcWdc--


--===============0672833549759252330==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: base64
Content-Disposition: inline

LS0gCnVidW50dS1zZWN1cml0eS1hbm5vdW5jZSBtYWlsaW5nIGxpc3QKdWJ1bnR1LXNlY3VyaXR5
LWFubm91bmNlQGxpc3RzLnVidW50dS5jb20KTW9kaWZ5IHNldHRpbmdzIG9yIHVuc3Vic2NyaWJl
IGF0OiBodHRwczovL2xpc3RzLnVidW50dS5jb20vbWFpbG1hbi9saXN0aW5mby91YnVudHUtc2Vj
dXJpdHktYW5ub3VuY2UK

--===============0672833549759252330==--
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung