Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2023-4949

Опубликовано: 10 нояб. 2023
Источник: debian
EPSS Низкий

Описание

An attacker with local access to a system (either through a disk or external drive) can present a modified XFS partition to grub-legacy in such a way to exploit a memory corruption in grub’s XFS file system implementation.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
grubunfixedpackage

Примечания

  • https://xenbits.xenproject.org/xsa/advisory-443.html

  • grub-legancy has not secure boot support. The CVE is specific for the src:grub

  • issue "An attacker with local access to a system (either through a disk or external

  • drive) can present a modified XFS partition to grub-legacy in such a way to exploit

  • a memory corruption in grub's XFS file system implementation."

EPSS

Процентиль: 9%
0.00032
Низкий

Связанные уязвимости

CVSS3: 8.1
ubuntu
около 2 лет назад

An attacker with local access to a system (either through a disk or external drive) can present a modified XFS partition to grub-legacy in such a way to exploit a memory corruption in grub’s XFS file system implementation.

CVSS3: 8.1
nvd
около 2 лет назад

An attacker with local access to a system (either through a disk or external drive) can present a modified XFS partition to grub-legacy in such a way to exploit a memory corruption in grub’s XFS file system implementation.

EPSS

Процентиль: 9%
0.00032
Низкий