Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4w23-87xc-gg8q

Опубликовано: 28 апр. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.7

Описание

NVIDIA Jetson Linux Driver Package contains a vulnerability in the Cboot ext4_read_file function, where insufficient validation of untrusted data may allow a highly privileged local attacker to cause a integer overflow, which may lead to code execution, escalation of privileges, limited denial of service, and some impact to confidentiality and integrity.

NVIDIA Jetson Linux Driver Package contains a vulnerability in the Cboot ext4_read_file function, where insufficient validation of untrusted data may allow a highly privileged local attacker to cause a integer overflow, which may lead to code execution, escalation of privileges, limited denial of service, and some impact to confidentiality and integrity.

EPSS

Процентиль: 19%
0.00062
Низкий

5.7 Medium

CVSS3

Дефекты

CWE-190

Связанные уязвимости

CVSS3: 5.7
nvd
почти 4 года назад

NVIDIA Jetson Linux Driver Package contains a vulnerability in the Cboot ext4_read_file function, where insufficient validation of untrusted data may allow a highly privileged local attacker to cause a integer overflow, which may lead to code execution, escalation of privileges, limited denial of service, and some impact to confidentiality and integrity. The scope of impact can extend to other components.

CVSS3: 5.7
fstec
почти 4 года назад

Уязвимость функции ext4_read_file модуля Cboot пакета драйверов микропрограммного обеспечения вычислительных плат NVIDIA Jetson, позволяющая нарушителю выполнить произвольный код, повысить свои привилегии или вызвать частичный отказ в обслуживании

EPSS

Процентиль: 19%
0.00062
Низкий

5.7 Medium

CVSS3

Дефекты

CWE-190