tftp.c in libslirp 4.1.0, as used in QEMU 4.2.0, does not prevent ..\ directory traversal on Windows.
[
{
"id": "CVE-2020-7211-ac505295",
"deprecated": false,
"digest": {
"length": 2682.0,
"function_hash": "120643303157668002325465674923733077484"
},
"signature_version": "v1",
"target": {
"function": "tftp_handle_rrq",
"file": "src/tftp.c"
},
"signature_type": "Function",
"source": "https://gitlab.freedesktop.org/slirp/libslirp@14ec36e107a8c9af7d0a80c3571fe39b291ff1d4"
},
{
"id": "CVE-2020-7211-ad897835",
"deprecated": false,
"digest": {
"line_hashes": [
"335400942427289243216194261493011164826",
"112539507008349734606060646785474580570",
"6747955274008167017013603513309967456",
"321079386013491220200005200596066450513",
"213290603849672081954127312170418223250"
],
"threshold": 0.9
},
"signature_version": "v1",
"target": {
"file": "src/tftp.c"
},
"signature_type": "Line",
"source": "https://gitlab.freedesktop.org/slirp/libslirp@14ec36e107a8c9af7d0a80c3571fe39b291ff1d4"
}
]