Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-45780

Опубликовано: 03 мар. 2025
Источник: debian
EPSS Низкий

Описание

A flaw was found in grub2. When reading tar files, grub2 allocates an internal buffer for the file name. However, it fails to properly verify the allocation against possible integer overflows. It's possible to cause the allocation length to overflow with a crafted tar file, leading to a heap out-of-bounds write. This flaw eventually allows an attacker to circumvent secure boot protections.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
grub2fixed2.12-6package
grub2fixed2.06-13+deb12u2bookwormpackage

Примечания

  • https://lists.gnu.org/archive/html/grub-devel/2025-02/msg00024.html

  • https://www.openwall.com/lists/oss-security/2025/02/18/3

EPSS

Процентиль: 17%
0.00262
Низкий

Связанные уязвимости

CVSS3: 6.7
ubuntu
больше 1 года назад

A flaw was found in grub2. When reading tar files, grub2 allocates an internal buffer for the file name. However, it fails to properly verify the allocation against possible integer overflows. It's possible to cause the allocation length to overflow with a crafted tar file, leading to a heap out-of-bounds write. This flaw eventually allows an attacker to circumvent secure boot protections.

CVSS3: 6.7
redhat
больше 1 года назад

A flaw was found in grub2. When reading tar files, grub2 allocates an internal buffer for the file name. However, it fails to properly verify the allocation against possible integer overflows. It's possible to cause the allocation length to overflow with a crafted tar file, leading to a heap out-of-bounds write. This flaw eventually allows an attacker to circumvent secure boot protections.

CVSS3: 6.7
nvd
больше 1 года назад

A flaw was found in grub2. When reading tar files, grub2 allocates an internal buffer for the file name. However, it fails to properly verify the allocation against possible integer overflows. It's possible to cause the allocation length to overflow with a crafted tar file, leading to a heap out-of-bounds write. This flaw eventually allows an attacker to circumvent secure boot protections.

CVSS3: 6.7
msrc
11 месяцев назад

Grub2: fs/tar: integer overflow causes heap oob write

CVSS3: 6.7
github
больше 1 года назад

A flaw was found in grub2. When reading tar files, grub2 allocates an internal buffer for the file name. However, it fails to properly verify the allocation against possible integer overflows. It's possible to cause the allocation length to overflow with a crafted tar file, leading to a heap out-of-bounds write. This flaw eventually allows an attacker to circumvent secure boot protections.

EPSS

Процентиль: 17%
0.00262
Низкий