CVE-2019-14378

Source
https://cve.org/CVERecord?id=CVE-2019-14378
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-14378.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2019-14378
Downstream
Related
Published
2019-07-29T11:15:11.577Z
Modified
2026-07-08T20:14:58.268085Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

ipreass in ipinput.c in libslirp 4.0.0 has a heap-based buffer overflow via a large packet because it mishandles a case involving the first fragment.

References

Affected packages

Git / github.com/spring-projects/spring-framework

Affected ranges

Type
GIT
Repo
https://github.com/spring-projects/spring-framework
Events
Database specific
{
    "extracted_events": [
        {
            "introduced": "4.0.0"
        },
        {
            "last_affected": "4.0.0"
        }
    ],
    "cpe": "cpe:2.3:a:libslirp_project:libslirp:4.0.0:*:*:*:*:*:*:*",
    "source": "CPE_STRING"
}

Affected versions

4.*
4.0.0
v4.*
v4.0.0.RELEASE

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-14378.json"

Git / gitlab.freedesktop.org/slirp/libslirp

Affected ranges

Type
GIT
Repo
https://gitlab.freedesktop.org/slirp/libslirp
Events
Database specific
{
    "extracted_events": [
        {
            "introduced": "4.0.0"
        },
        {
            "last_affected": "4.0.0"
        }
    ],
    "cpe": "cpe:2.3:a:libslirp_project:libslirp:4.0.0:*:*:*:*:*:*:*",
    "source": [
        "CPE_STRING",
        "REFERENCES"
    ]
}

Affected versions

4.*
4.0.0
v4.*
v4.0.0

Database specific

vanir_signatures_modified
"2026-07-08T20:14:58Z"
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-14378.json"
vanir_signatures
[
    {
        "signature_type": "Line",
        "target": {
            "file": "src/ip_input.c"
        },
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "317361430190225003347536229565579127684",
                "32876557084403352590041593915771637096",
                "329287438392875335896608726947175177095",
                "86677765742023927759653894039043670774",
                "313169288687725037738192364702706909465",
                "156244072918945693710603918551038402869",
                "276087485554849238538926261260840071705"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2019-14378-303b7146",
        "source": "https://gitlab.freedesktop.org/slirp/libslirp@126c04acbabd7ad32c2b018fe10dfac2a3bc1210",
        "signature_version": "v1"
    },
    {
        "signature_type": "Function",
        "target": {
            "file": "src/ip_input.c",
            "function": "ip_reass"
        },
        "deprecated": false,
        "digest": {
            "length": 2835.0,
            "function_hash": "228952944605302490550765160498435836668"
        },
        "id": "CVE-2019-14378-4d99f843",
        "source": "https://gitlab.freedesktop.org/slirp/libslirp@126c04acbabd7ad32c2b018fe10dfac2a3bc1210",
        "signature_version": "v1"
    }
]