Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-9763

Опубликовано: 19 июн. 2017
Источник: debian

Описание

The grub_ext2_read_block function in fs/ext2.c in GNU GRUB before 2013-11-12, as used in shlr/grub/fs/ext2.c in radare2 1.5.0, allows remote attackers to cause a denial of service (excessive stack use and application crash) via a crafted binary file, related to use of a variable-size stack array.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
grub2fixed2.02~beta2-8package
radare2fixed1.6.0+dfsg-1package
radare2no-dsajessiepackage
radare2no-dsawheezypackage

Примечания

  • https://github.com/radare/radare2/commit/65000a7fd9eea62359e6d6714f17b94a99a82edd

  • https://github.com/radare/radare2/issues/7723

  • Not a security issue for Grub

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 8 лет назад

The grub_ext2_read_block function in fs/ext2.c in GNU GRUB before 2013-11-12, as used in shlr/grub/fs/ext2.c in radare2 1.5.0, allows remote attackers to cause a denial of service (excessive stack use and application crash) via a crafted binary file, related to use of a variable-size stack array.

CVSS3: 3.3
redhat
больше 8 лет назад

The grub_ext2_read_block function in fs/ext2.c in GNU GRUB before 2013-11-12, as used in shlr/grub/fs/ext2.c in radare2 1.5.0, allows remote attackers to cause a denial of service (excessive stack use and application crash) via a crafted binary file, related to use of a variable-size stack array.

CVSS3: 7.5
nvd
больше 8 лет назад

The grub_ext2_read_block function in fs/ext2.c in GNU GRUB before 2013-11-12, as used in shlr/grub/fs/ext2.c in radare2 1.5.0, allows remote attackers to cause a denial of service (excessive stack use and application crash) via a crafted binary file, related to use of a variable-size stack array.

suse-cvrf
почти 7 лет назад

Security update for grub2

CVSS3: 7.5
github
больше 3 лет назад

The grub_ext2_read_block function in fs/ext2.c in GNU GRUB before 2013-11-12, as used in shlr/grub/fs/ext2.c in radare2 1.5.0, allows remote attackers to cause a denial of service (excessive stack use and application crash) via a crafted binary file, related to use of a variable-size stack array.