Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5hp2-x786-x3fq

Опубликовано: 19 фев. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 6.7

Описание

A flaw was found in grub2. The calculation of the translation buffer when reading a language .mo file in grub_gettext_getstr_from_position() may overflow, leading to a Out-of-bound write. This issue can be leveraged by an attacker to overwrite grub2's sensitive heap data, eventually leading to the circumvention of secure boot protections.

A flaw was found in grub2. The calculation of the translation buffer when reading a language .mo file in grub_gettext_getstr_from_position() may overflow, leading to a Out-of-bound write. This issue can be leveraged by an attacker to overwrite grub2's sensitive heap data, eventually leading to the circumvention of secure boot protections.

EPSS

Процентиль: 5%
0.00024
Низкий

6.7 Medium

CVSS3

Дефекты

CWE-787

Связанные уязвимости

CVSS3: 6.7
ubuntu
7 месяцев назад

A flaw was found in grub2. The calculation of the translation buffer when reading a language .mo file in grub_gettext_getstr_from_position() may overflow, leading to a Out-of-bound write. This issue can be leveraged by an attacker to overwrite grub2's sensitive heap data, eventually leading to the circumvention of secure boot protections.

CVSS3: 6.7
redhat
7 месяцев назад

A flaw was found in grub2. The calculation of the translation buffer when reading a language .mo file in grub_gettext_getstr_from_position() may overflow, leading to a Out-of-bound write. This issue can be leveraged by an attacker to overwrite grub2's sensitive heap data, eventually leading to the circumvention of secure boot protections.

CVSS3: 6.7
nvd
7 месяцев назад

A flaw was found in grub2. The calculation of the translation buffer when reading a language .mo file in grub_gettext_getstr_from_position() may overflow, leading to a Out-of-bound write. This issue can be leveraged by an attacker to overwrite grub2's sensitive heap data, eventually leading to the circumvention of secure boot protections.

CVSS3: 6.7
debian
7 месяцев назад

A flaw was found in grub2. The calculation of the translation buffer w ...

CVSS3: 7.8
fstec
7 месяцев назад

Уязвимость компонента gettext загрузчика операционных систем Grub2, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 5%
0.00024
Низкий

6.7 Medium

CVSS3

Дефекты

CWE-787