Debian Security Advisory
DLA-2090-1 qemu -- LTS security update
- Date Reported:
- 05 Feb 2020
- Affected Packages:
- qemu
- Vulnerable:
- Yes
- Security database references:
- In the Debian bugtracking system: Bug 949085.
In Mitre's CVE dictionary: CVE-2020-7039. - More information:
-
tcp_emu in tcp_subr.c in libslirp 4.1.0, as used in QEMU 4.2.0, mismanages memory, as demonstrated by IRC DCC commands in EMU_IRC. This can cause a heap-based buffer overflow or other out-of-bounds access which can lead to a DoS or potential execute arbitrary code.
For Debian 8
Jessie
, this problem has been fixed in version 1:2.1+dfsg-12+deb8u13.We recommend that you upgrade your qemu packages.
Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS