CVE-2020-7211

HIGH

libslirp 4.1.0 - Path Traversal via TFTP Directory Traversal

Title source: llm
STIX 2.1

Description

tftp.c in libslirp 4.1.0, as used in QEMU 4.2.0, does not prevent ..\ directory traversal on Windows.

References (3)

Core 3
Core References
Mailing List, Third Party Advisory x_refsource_confirm
http://www.openwall.com/lists/oss-security/2020/01/17/2
Third Party Advisory vendor-advisory x_refsource_debian
https://security-tracker.debian.org/tracker/CVE-2020-7211

Scores

CVSS v3 7.5
EPSS 0.0031
EPSS Percentile 53.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-22
Status published
Products (2)
libslirp_project/libslirp 4.1.0
qemu/qemu 4.2.0
Published Jan 21, 2020
Tracked Since Feb 18, 2026