Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pr45-j47f-755r

Опубликовано: 07 июл. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7

Описание

A crafted JPEG image may lead the JPEG reader to underflow its data pointer, allowing user-controlled data to be written in heap. To a successful to be performed the attacker needs to perform some triage over the heap layout and craft an image with a malicious format and payload. This vulnerability can lead to data corruption and eventual code execution or secure boot circumvention. This flaw affects grub2 versions prior grub-2.12.

A crafted JPEG image may lead the JPEG reader to underflow its data pointer, allowing user-controlled data to be written in heap. To a successful to be performed the attacker needs to perform some triage over the heap layout and craft an image with a malicious format and payload. This vulnerability can lead to data corruption and eventual code execution or secure boot circumvention. This flaw affects grub2 versions prior grub-2.12.

EPSS

Процентиль: 21%
0.00067
Низкий

7 High

CVSS3

Дефекты

CWE-787

Связанные уязвимости

CVSS3: 7
ubuntu
больше 3 лет назад

A crafted JPEG image may lead the JPEG reader to underflow its data pointer, allowing user-controlled data to be written in heap. To a successful to be performed the attacker needs to perform some triage over the heap layout and craft an image with a malicious format and payload. This vulnerability can lead to data corruption and eventual code execution or secure boot circumvention. This flaw affects grub2 versions prior grub-2.12.

CVSS3: 7.5
redhat
больше 3 лет назад

A crafted JPEG image may lead the JPEG reader to underflow its data pointer, allowing user-controlled data to be written in heap. To a successful to be performed the attacker needs to perform some triage over the heap layout and craft an image with a malicious format and payload. This vulnerability can lead to data corruption and eventual code execution or secure boot circumvention. This flaw affects grub2 versions prior grub-2.12.

CVSS3: 7
nvd
больше 3 лет назад

A crafted JPEG image may lead the JPEG reader to underflow its data pointer, allowing user-controlled data to be written in heap. To a successful to be performed the attacker needs to perform some triage over the heap layout and craft an image with a malicious format and payload. This vulnerability can lead to data corruption and eventual code execution or secure boot circumvention. This flaw affects grub2 versions prior grub-2.12.

CVSS3: 7
msrc
около 2 лет назад

Описание отсутствует

CVSS3: 7
debian
больше 3 лет назад

A crafted JPEG image may lead the JPEG reader to underflow its data po ...

EPSS

Процентиль: 21%
0.00067
Низкий

7 High

CVSS3

Дефекты

CWE-787