Errata overview
Errata ID 434
Date 2020-02-05
Source package qemu
Fixed in version 1:2.8+dfsg-6+deb9u9A~4.4.3.202002050747
Description
This update addresses the following issues:
* Slirp: use-after-free during packet reassembly (CVE-2019-15890)
* slirp: Out-of-bounds buffer access while emulating tcp protocols in
  `tcp_emu()` (CVE-2020-7039)
Additional notes
CVE ID CVE-2019-15890
CVE-2020-7039
UCS Bug number #50779