Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5hp2-x786-x3fq

Опубликовано: 19 фев. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 6.7

Описание

A flaw was found in grub2. The calculation of the translation buffer when reading a language .mo file in grub_gettext_getstr_from_position() may overflow, leading to a Out-of-bound write. This issue can be leveraged by an attacker to overwrite grub2's sensitive heap data, eventually leading to the circumvention of secure boot protections.

A flaw was found in grub2. The calculation of the translation buffer when reading a language .mo file in grub_gettext_getstr_from_position() may overflow, leading to a Out-of-bound write. This issue can be leveraged by an attacker to overwrite grub2's sensitive heap data, eventually leading to the circumvention of secure boot protections.

EPSS

Процентиль: 6%
0.00028
Низкий

6.7 Medium

CVSS3

Дефекты

CWE-787

Связанные уязвимости

CVSS3: 6.7
ubuntu
9 месяцев назад

A flaw was found in grub2. The calculation of the translation buffer when reading a language .mo file in grub_gettext_getstr_from_position() may overflow, leading to a Out-of-bound write. This issue can be leveraged by an attacker to overwrite grub2's sensitive heap data, eventually leading to the circumvention of secure boot protections.

CVSS3: 6.7
redhat
9 месяцев назад

A flaw was found in grub2. The calculation of the translation buffer when reading a language .mo file in grub_gettext_getstr_from_position() may overflow, leading to a Out-of-bound write. This issue can be leveraged by an attacker to overwrite grub2's sensitive heap data, eventually leading to the circumvention of secure boot protections.

CVSS3: 6.7
nvd
9 месяцев назад

A flaw was found in grub2. The calculation of the translation buffer when reading a language .mo file in grub_gettext_getstr_from_position() may overflow, leading to a Out-of-bound write. This issue can be leveraged by an attacker to overwrite grub2's sensitive heap data, eventually leading to the circumvention of secure boot protections.

CVSS3: 6.7
msrc
2 месяца назад

Grub2: grub-core/gettext: integer overflow leads to heap oob write.

CVSS3: 6.7
debian
9 месяцев назад

A flaw was found in grub2. The calculation of the translation buffer w ...

EPSS

Процентиль: 6%
0.00028
Низкий

6.7 Medium

CVSS3

Дефекты

CWE-787