Debian Security Advisory

DLA-2090-1 qemu -- LTS security update

Date Reported:
05 Feb 2020
Affected Packages:
qemu
Vulnerable:
Yes
Security database references:
In the Debian bugtracking system: Bug 949085.
In Mitre's CVE dictionary: CVE-2020-7039.
More information:

tcp_emu in tcp_subr.c in libslirp 4.1.0, as used in QEMU 4.2.0, mismanages memory, as demonstrated by IRC DCC commands in EMU_IRC. This can cause a heap-based buffer overflow or other out-of-bounds access which can lead to a DoS or potential execute arbitrary code.

For Debian 8 Jessie, this problem has been fixed in version 1:2.1+dfsg-12+deb8u13.

We recommend that you upgrade your qemu packages.

Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS