tftp.c in libslirp 4.1.0, as used in QEMU 4.2.0, does not prevent ..\ directory traversal on Windows.
{ "vanir_signatures": [ { "digest": { "length": 2682.0, "function_hash": "120643303157668002325465674923733077484" }, "target": { "file": "src/tftp.c", "function": "tftp_handle_rrq" }, "signature_version": "v1", "id": "CVE-2020-7211-ac505295", "deprecated": false, "signature_type": "Function", "source": "https://gitlab.freedesktop.org/slirp/libslirp@14ec36e107a8c9af7d0a80c3571fe39b291ff1d4" }, { "digest": { "threshold": 0.9, "line_hashes": [ "335400942427289243216194261493011164826", "112539507008349734606060646785474580570", "6747955274008167017013603513309967456", "321079386013491220200005200596066450513", "213290603849672081954127312170418223250" ] }, "target": { "file": "src/tftp.c" }, "signature_version": "v1", "id": "CVE-2020-7211-ad897835", "deprecated": false, "signature_type": "Line", "source": "https://gitlab.freedesktop.org/slirp/libslirp@14ec36e107a8c9af7d0a80c3571fe39b291ff1d4" } ] }