Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gc7m-mhr5-phfh

Опубликовано: 05 дек. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 8.1

Описание

Multiple data integrity vulnerabilities exist in the package hash checking functionality of Buildroot 2023.08.1 and Buildroot dev commit 622698d7847. A specially crafted man-in-the-middle attack can lead to arbitrary command execution in the builder.This vulnerability is related to the mxsldr package.

Multiple data integrity vulnerabilities exist in the package hash checking functionality of Buildroot 2023.08.1 and Buildroot dev commit 622698d7847. A specially crafted man-in-the-middle attack can lead to arbitrary command execution in the builder.This vulnerability is related to the mxsldr package.

EPSS

Процентиль: 26%
0.00089
Низкий

8.1 High

CVSS3

Дефекты

CWE-494

Связанные уязвимости

CVSS3: 8.1
nvd
около 2 лет назад

Multiple data integrity vulnerabilities exist in the package hash checking functionality of Buildroot 2023.08.1 and Buildroot dev commit 622698d7847. A specially crafted man-in-the-middle attack can lead to arbitrary command execution in the builder.This vulnerability is related to the `mxsldr` package.

EPSS

Процентиль: 26%
0.00089
Низкий

8.1 High

CVSS3

Дефекты

CWE-494