CVE-2020-7211
HIGHCVSS 7.5/10EPSS 4.14%
Last modified
CVE-2020-7211 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. tftp.c in libslirp 4.1.0, as used in QEMU 4.2.0, does not prevent ..\ directory traversal on Windows.. EPSS estimates a 4.14% chance of exploitation in the next 30 days.
Description
tftp.c in libslirp 4.1.0, as used in QEMU 4.2.0, does not prevent ..\ directory traversal on Windows.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Libslirp Project | Libslirp | 4.1.0 |
| Qemu | Qemu | 4.2.0 |
References
- https://www.openwall.com/lists/oss-security/2020/01/17/2Mailing List, Third Party Advisory
- https://gitlab.freedesktop.org/slirp/libslirp/commit/14ec36e107a8c9af7d0a80c3571fe39b291ff1d4Patch, Third Party Advisory
- https://security-tracker.debian.org/tracker/CVE-2020-7211Third Party Advisory
- https://www.openwall.com/lists/oss-security/2020/01/17/2Mailing List, Third Party Advisory
- https://gitlab.freedesktop.org/slirp/libslirp/commit/14ec36e107a8c9af7d0a80c3571fe39b291ff1d4Patch, Third Party Advisory
- https://security-tracker.debian.org/tracker/CVE-2020-7211Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-7211?
tftp.c in libslirp 4.1.0, as used in QEMU 4.2.0, does not prevent ..\ directory traversal on Windows.
How severe is CVE-2020-7211?
CVE-2020-7211 has a CVSS score of 7.5/10 (HIGH severity). The EPSS model estimates a 4.14% probability of exploitation in the next 30 days.
How do I fix CVE-2020-7211?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-7205A potential security vulnerability has been identified in HP…6.7
- CVE-2020-7206HP nagios plugin for iLO (nagios-plugins-hpilo v1.50 and ear…9.8
- CVE-2020-7207A local elevation of privilege using physical access securit…6.8
- CVE-2020-7208LinuxKI v6.0-1 and earlier is vulnerable to an XSS which is …6.1
- CVE-2020-7209LinuxKI v6.0-1 and earlier is vulnerable to an remote code e…9.8
- CVE-2020-7210Umbraco CMS 8.2.2 allows CSRF to enable/disable or delete us…4.3
- CVE-2020-7212The _encode_invalid_chars function in util/url.py in the url…7.5
- CVE-2020-7213Parallels 13 uses cleartext HTTP as part of the update proce…7.5
- CVE-2020-7215An issue was discovered in Gallagher Command Centre 7.x befo…5.5
- CVE-2020-7216An ni_dhcp4_parse_response memory leak in openSUSE wicked 0.…7.5
- CVE-2020-7217An ni_dhcp4_fsm_process_dhcp4_packet memory leak in openSUSE…7.5
- CVE-2020-7218HashiCorp Nomad and Nonad Enterprise up to 0.10.2 HTTP/RPC s…7.5
Are you affected by CVE-2020-7211?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
