Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8whj-mpcj-4jv6

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.7

Описание

There's an issue with grub2 in all versions before 2.06 when handling squashfs filesystems containing a symbolic link with name length of UINT32 bytes in size. The name size leads to an arithmetic overflow leading to a zero-size allocation further causing a heap-based buffer overflow with attacker controlled data.

There's an issue with grub2 in all versions before 2.06 when handling squashfs filesystems containing a symbolic link with name length of UINT32 bytes in size. The name size leads to an arithmetic overflow leading to a zero-size allocation further causing a heap-based buffer overflow with attacker controlled data.

EPSS

Процентиль: 14%
0.00047
Низкий

6.7 Medium

CVSS3

Дефекты

CWE-190
CWE-787

Связанные уязвимости

CVSS3: 6.7
ubuntu
почти 5 лет назад

There's an issue with grub2 in all versions before 2.06 when handling squashfs filesystems containing a symbolic link with name length of UINT32 bytes in size. The name size leads to an arithmetic overflow leading to a zero-size allocation further causing a heap-based buffer overflow with attacker controlled data.

CVSS3: 6.7
redhat
почти 5 лет назад

There's an issue with grub2 in all versions before 2.06 when handling squashfs filesystems containing a symbolic link with name length of UINT32 bytes in size. The name size leads to an arithmetic overflow leading to a zero-size allocation further causing a heap-based buffer overflow with attacker controlled data.

CVSS3: 6.7
nvd
почти 5 лет назад

There's an issue with grub2 in all versions before 2.06 when handling squashfs filesystems containing a symbolic link with name length of UINT32 bytes in size. The name size leads to an arithmetic overflow leading to a zero-size allocation further causing a heap-based buffer overflow with attacker controlled data.

CVSS3: 6.7
msrc
почти 5 лет назад

Описание отсутствует

CVSS3: 6.7
debian
почти 5 лет назад

There's an issue with grub2 in all versions before 2.06 when handling ...

EPSS

Процентиль: 14%
0.00047
Низкий

6.7 Medium

CVSS3

Дефекты

CWE-190
CWE-787