Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-3696

Опубликовано: 07 июн. 2022
Источник: redhat
CVSS3: 5

Описание

A heap out-of-bounds write may heppen during the handling of Huffman tables in the PNG reader. This may lead to data corruption in the heap space. Confidentiality, Integrity and Availablity impact may be considered Low as it's very complex to an attacker control the encoding and positioning of corrupted Huffman entries to achieve results such as arbitrary code execution and/or secure boot circumvention. This flaw affects grub2 versions prior grub-2.12.

A flaw was found in grub2 when handling a PNG image header. When decoding the data contained in the Huffman table at the PNG file header, an out-of-bounds write may happen on grub's heap.

Отчет

This vulnerability's impact on confidentiality, data integrity, and availability are considered low as a successful attack using this flaw is very complex.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7grub2Out of support scope
Red Hat Enterprise Linux 8grub2FixedRHSA-2022:509516.06.2022
Red Hat Enterprise Linux 8.1 Update Services for SAP Solutionsgrub2FixedRHSA-2022:509816.06.2022
Red Hat Enterprise Linux 8.2 Extended Update Supportgrub2FixedRHSA-2022:510016.06.2022
Red Hat Enterprise Linux 8.4 Extended Update Supportgrub2FixedRHSA-2022:509616.06.2022
Red Hat Enterprise Linux 9grub2FixedRHSA-2022:509916.06.2022

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=1991686grub2: Crafted PNG image may lead to out-of-bound write during huffman table handling

5 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.5
ubuntu
почти 3 года назад

A heap out-of-bounds write may heppen during the handling of Huffman tables in the PNG reader. This may lead to data corruption in the heap space. Confidentiality, Integrity and Availablity impact may be considered Low as it's very complex to an attacker control the encoding and positioning of corrupted Huffman entries to achieve results such as arbitrary code execution and/or secure boot circumvention. This flaw affects grub2 versions prior grub-2.12.

CVSS3: 4.5
nvd
почти 3 года назад

A heap out-of-bounds write may heppen during the handling of Huffman tables in the PNG reader. This may lead to data corruption in the heap space. Confidentiality, Integrity and Availablity impact may be considered Low as it's very complex to an attacker control the encoding and positioning of corrupted Huffman entries to achieve results such as arbitrary code execution and/or secure boot circumvention. This flaw affects grub2 versions prior grub-2.12.

CVSS3: 4.5
msrc
больше 1 года назад

Описание отсутствует

CVSS3: 4.5
debian
почти 3 года назад

A heap out-of-bounds write may heppen during the handling of Huffman t ...

CVSS3: 4.5
github
почти 3 года назад

A heap out-of-bounds write may heppen during the handling of Huffman tables in the PNG reader. This may lead to data corruption in the heap space. Confidentiality, Integrity and Availablity impact may be considered Low as it's very complex to an attacker control the encoding and positioning of corrupted Huffman entries to achieve results such as arbitrary code execution and/or secure boot circumvention. This flaw affects grub2 versions prior grub-2.12.

5 Medium

CVSS3