Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-h8v2-pvw7-3jf5

Опубликовано: 20 июл. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 8.1

Описание

Out-of-bounds write when handling split HTTP headers; When handling split HTTP headers, GRUB2 HTTP code accidentally moves its internal data buffer point by one position. This can lead to a out-of-bound write further when parsing the HTTP request, writing a NULL byte past the buffer. It's conceivable that an attacker controlled set of packets can lead to corruption of the GRUB2's internal memory metadata.

Out-of-bounds write when handling split HTTP headers; When handling split HTTP headers, GRUB2 HTTP code accidentally moves its internal data buffer point by one position. This can lead to a out-of-bound write further when parsing the HTTP request, writing a NULL byte past the buffer. It's conceivable that an attacker controlled set of packets can lead to corruption of the GRUB2's internal memory metadata.

EPSS

Процентиль: 35%
0.00141
Низкий

8.1 High

CVSS3

Дефекты

CWE-787

Связанные уязвимости

CVSS3: 8.1
ubuntu
почти 2 года назад

Out-of-bounds write when handling split HTTP headers; When handling split HTTP headers, GRUB2 HTTP code accidentally moves its internal data buffer point by one position. This can lead to a out-of-bound write further when parsing the HTTP request, writing a NULL byte past the buffer. It's conceivable that an attacker controlled set of packets can lead to corruption of the GRUB2's internal memory metadata.

CVSS3: 7
redhat
около 3 лет назад

Out-of-bounds write when handling split HTTP headers; When handling split HTTP headers, GRUB2 HTTP code accidentally moves its internal data buffer point by one position. This can lead to a out-of-bound write further when parsing the HTTP request, writing a NULL byte past the buffer. It's conceivable that an attacker controlled set of packets can lead to corruption of the GRUB2's internal memory metadata.

CVSS3: 8.1
nvd
почти 2 года назад

Out-of-bounds write when handling split HTTP headers; When handling split HTTP headers, GRUB2 HTTP code accidentally moves its internal data buffer point by one position. This can lead to a out-of-bound write further when parsing the HTTP request, writing a NULL byte past the buffer. It's conceivable that an attacker controlled set of packets can lead to corruption of the GRUB2's internal memory metadata.

CVSS3: 7
msrc
почти 2 года назад

Описание отсутствует

CVSS3: 8.1
debian
почти 2 года назад

Out-of-bounds write when handling split HTTP headers; When handling sp ...

EPSS

Процентиль: 35%
0.00141
Низкий

8.1 High

CVSS3

Дефекты

CWE-787