Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pr45-j47f-755r

Опубликовано: 07 июл. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7

Описание

A crafted JPEG image may lead the JPEG reader to underflow its data pointer, allowing user-controlled data to be written in heap. To a successful to be performed the attacker needs to perform some triage over the heap layout and craft an image with a malicious format and payload. This vulnerability can lead to data corruption and eventual code execution or secure boot circumvention. This flaw affects grub2 versions prior grub-2.12.

A crafted JPEG image may lead the JPEG reader to underflow its data pointer, allowing user-controlled data to be written in heap. To a successful to be performed the attacker needs to perform some triage over the heap layout and craft an image with a malicious format and payload. This vulnerability can lead to data corruption and eventual code execution or secure boot circumvention. This flaw affects grub2 versions prior grub-2.12.

EPSS

Процентиль: 18%
0.00058
Низкий

7 High

CVSS3

Дефекты

CWE-787

Связанные уязвимости

CVSS3: 7
ubuntu
почти 3 года назад

A crafted JPEG image may lead the JPEG reader to underflow its data pointer, allowing user-controlled data to be written in heap. To a successful to be performed the attacker needs to perform some triage over the heap layout and craft an image with a malicious format and payload. This vulnerability can lead to data corruption and eventual code execution or secure boot circumvention. This flaw affects grub2 versions prior grub-2.12.

CVSS3: 7.5
redhat
около 3 лет назад

A crafted JPEG image may lead the JPEG reader to underflow its data pointer, allowing user-controlled data to be written in heap. To a successful to be performed the attacker needs to perform some triage over the heap layout and craft an image with a malicious format and payload. This vulnerability can lead to data corruption and eventual code execution or secure boot circumvention. This flaw affects grub2 versions prior grub-2.12.

CVSS3: 7
nvd
почти 3 года назад

A crafted JPEG image may lead the JPEG reader to underflow its data pointer, allowing user-controlled data to be written in heap. To a successful to be performed the attacker needs to perform some triage over the heap layout and craft an image with a malicious format and payload. This vulnerability can lead to data corruption and eventual code execution or secure boot circumvention. This flaw affects grub2 versions prior grub-2.12.

CVSS3: 7
msrc
больше 1 года назад

Описание отсутствует

CVSS3: 7
debian
почти 3 года назад

A crafted JPEG image may lead the JPEG reader to underflow its data po ...

EPSS

Процентиль: 18%
0.00058
Низкий

7 High

CVSS3

Дефекты

CWE-787