libslirp (4.1.0-2ubuntu2) focal; urgency=medium * SECURITY UPDATE: use-after-free in ip_reass() - debian/patches/CVE-2020-1983.patch: fix buffer handling in src/ip_input.c. - CVE-2020-1983 -- Marc Deslauriers Tue, 21 Apr 2020 07:18:28 -0400 libslirp (4.1.0-2ubuntu1) focal; urgency=medium * SECURITY UPDATE: buffer overflow via incorrect snprintf return codes - debian/patches/ubuntu/CVE-2020-8608-1.patch: add slirp_fmt() helpers to src/util.c, src/util.h. - debian/patches/ubuntu/CVE-2020-8608-2.patch: fix unsafe snprintf() usages in src/tcp_subr.c. - CVE-2020-8608 -- Marc Deslauriers Wed, 19 Feb 2020 08:57:46 -0500 libslirp (4.1.0-2) unstable; urgency=high * Closes: #949084, CVE-2020-7039: OOB buffer access while emulating tcp protocols in tcp_emu() This includes 3 patches: tcp_emu-fix-OOB-access-CVE-2020-7039.patch slirp-use-correct-size-while-emulating-commands-CVE-2020-7039.patch slirp-use-correct-size-while-emulating-IRC-commands-CVE-2020-7039.patch -- Michael Tokarev Fri, 17 Jan 2020 14:24:00 +0300 libslirp (4.1.0-1) unstable; urgency=medium * new upstream release (4.1.0) * remove all patches (now everything is included upstream) * included 2 new symbols to libslirp0.symbols -- Michael Tokarev Sat, 07 Dec 2019 16:10:42 +0300 libslirp (4.0.0-2) unstable; urgency=medium * fork_exec-correctly-parse-command-lines-that-contain-spaces.patch * bump Standards-Version to 4.4.1 (no changes) -- Michael Tokarev Thu, 28 Nov 2019 13:58:14 +0300 libslirp (4.0.0-1) unstable; urgency=medium * initial release -- Michael Tokarev Tue, 27 Aug 2019 15:55:43 +0300