In libslirp 4.1.0, as used in QEMU 4.2.0, tcp_subr.c misuses snprintf return values, leading to a buffer overflow in later code.
{ "vanir_signatures": [ { "signature_version": "v1", "target": { "file": "src/tcp_subr.c" }, "signature_type": "Line", "source": "https://gitlab.freedesktop.org/slirp/libslirp@68ccb8021a838066f0951d4b2817eb6b6f10a843", "deprecated": false, "digest": { "line_hashes": [ "246648876760480391059830316711041769480", "127439615238555046192080519638893348443", "223589317652917045666002013374394968170", "245596684563756949555195469012064437300", "194526991643005850067677639536938007027", "188893205728168835746341423704448688516", "282393555808581485874090025117595990314", "153431303589887970174056372056571214668", "25858351891616231709346514064225000812", "91982728810868740773815739603840717676", "317060831391956178219433144069180100685", "188893205728168835746341423704448688516", "92782018852356111485708160247098003542", "139311481486254240105809272040429908295", "149191584418569480501778977001248663817", "298045386813361464402400620012150195713", "272848814047538639148431331631225512190", "208323013283776806435445663037770380544", "236421557069710862660078927174498374671", "245674776238120024263612856855299285000", "267185354513032656647907935334471723415", "216933895929362785716587362691680375108", "62292012986368683187524842658639499442", "176029839855673906255372583779609769276", "132520196737418859885083555945567545859", "82162758469354334629913884814690013392", "336934841844850221297544373916342120898", "41361268106330889474799305467222635341", "100711868396011321646319668050873026326", "62292012986368683187524842658639499442", "77024491429738668846874679598737687986", "266114763669921623380735087941777007699", "285203754165203042380363300884601475109", "211022342319323311175830755330711834752", "96217543674087600064345527018584851810", "207095843971067530227188775095233988813", "62292012986368683187524842658639499442", "117259289927896706883870945701730633998", "92404445707750801789631655651031279228", "164102768652786240203980105465034849313", "292176810797231257996730492336267094302", "33450088625274173574651435422396885749", "261711723404151449456034420131531885862" ], "threshold": 0.9 }, "id": "CVE-2020-8608-6b31d243" }, { "signature_version": "v1", "target": { "function": "tcp_emu", "file": "src/tcp_subr.c" }, "signature_type": "Function", "source": "https://gitlab.freedesktop.org/slirp/libslirp@68ccb8021a838066f0951d4b2817eb6b6f10a843", "deprecated": false, "digest": { "length": 6616.0, "function_hash": "100197469861033783327683667740240832823" }, "id": "CVE-2020-8608-b1ef7348" } ] }