• libslirp vulnerability

    From bugz_ubuntu@21:4/110 to Ubuntu Users on Monday, July 27, 2020 12:10:09
    libslirp vulnerability

    A security issue affects these releases of Ubuntu and its
    derivatives:

    * Ubuntu 20.04 LTS

    Summary

    libslirp could be made to crash if it received specially crafted
    network traffic.

    Software Description

    * libslirp - None

    Details

    Ziming Zhang and VictorV discovered that libslirp incorrectly
    handled replying to certain ICMP echo requests. A remote attacker
    could possibly use this issue to cause libslirp to crash,
    resulting in a denial of service.

    Update instructions

    The problem can be corrected by updating your system to the
    following package versions:

    Ubuntu 20.04 LTS
    libslirp0 - 4.1.0-2ubuntu2.1

    To update your system, please follow these instructions:
    https://wiki.ubuntu.com/Security/Upgrades.

    After a standard system update you need to reboot your computer to
    make all the necessary changes.

    References

    * CVE-2020-10756

    --- Mystic BBS v1.12 A45 (Linux/64)
    * Origin: BZ&BZ BBS (21:4/110)