Π›ΠΎΠ³ΠΎΡ‚ΠΈΠΏ exploitDog
Консоль
Π›ΠΎΠ³ΠΎΡ‚ΠΈΠΏ exploitDog

exploitDog

ubuntu Π»ΠΎΠ³ΠΎΡ‚ΠΈΠΏ

CVE-2021-20225

ΠžΠΏΡƒΠ±Π»ΠΈΠΊΠΎΠ²Π°Π½ΠΎ: 03 ΠΌΠ°Ρ€. 2021
Π˜ΡΡ‚ΠΎΡ‡Π½ΠΈΠΊ: ubuntu
ΠŸΡ€ΠΈΠΎΡ€ΠΈΡ‚Π΅Ρ‚: medium
EPSS Низкий
CVSS2: 7.2
CVSS3: 6.7

ОписаниС

A flaw was found in grub2 in versions prior to 2.06. The option parser allows an attacker to write past the end of a heap-allocated buffer by calling certain commands with a large number of specific short forms of options. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

Π Π΅Π»ΠΈΠ·Π‘Ρ‚Π°Ρ‚ΡƒΡΠŸΡ€ΠΈΠΌΠ΅Ρ‡Π°Π½ΠΈΠ΅
bionic

ignored

end of standard support
devel

not-affected

does not affect Secure Boot
esm-infra-legacy/trusty

not-affected

does not affect Secure Boot
esm-infra/bionic

not-affected

does not affect Secure Boot
esm-infra/focal

not-affected

does not affect Secure Boot
esm-infra/xenial

not-affected

does not affect Secure Boot
focal

not-affected

does not affect Secure Boot
jammy

not-affected

does not affect Secure Boot
kinetic

not-affected

does not affect Secure Boot
lunar

not-affected

does not affect Secure Boot

ΠŸΠΎΠΊΠ°Π·Ρ‹Π²Π°Ρ‚ΡŒ ΠΏΠΎ

Π Π΅Π»ΠΈΠ·Π‘Ρ‚Π°Ρ‚ΡƒΡΠŸΡ€ΠΈΠΌΠ΅Ρ‡Π°Π½ΠΈΠ΅
bionic

released

1.167~18.04.5
devel

not-affected

1.193
esm-infra-legacy/trusty

needed

esm-infra/bionic

not-affected

1.167~18.04.5
esm-infra/focal

not-affected

1.167.2
esm-infra/xenial

not-affected

1.164
focal

released

1.167.2
groovy

released

1.167.2
hirsute

released

1.164
impish

released

1.169

ΠŸΠΎΠΊΠ°Π·Ρ‹Π²Π°Ρ‚ΡŒ ΠΏΠΎ

Π Π΅Π»ΠΈΠ·Π‘Ρ‚Π°Ρ‚ΡƒΡΠŸΡ€ΠΈΠΌΠ΅Ρ‡Π°Π½ΠΈΠ΅
bionic

released

2.04-1ubuntu44.1.2
devel

not-affected

2.06-2ubuntu17
esm-infra-legacy/trusty

DNE

esm-infra/bionic

not-affected

2.04-1ubuntu44.1.2
esm-infra/focal

not-affected

2.04-1ubuntu44.2
esm-infra/xenial

not-affected

2.04-1ubuntu42
focal

released

2.04-1ubuntu44.2
groovy

released

2.04-1ubuntu44.2
hirsute

released

2.04-1ubuntu42
impish

released

2.04-1ubuntu45

ΠŸΠΎΠΊΠ°Π·Ρ‹Π²Π°Ρ‚ΡŒ ΠΏΠΎ

Бсылки Π½Π° источники

EPSS

ΠŸΡ€ΠΎΡ†Π΅Π½Ρ‚ΠΈΠ»ΡŒ: 28%
0.00098
Низкий

7.2 High

CVSS2

6.7 Medium

CVSS3

БвязанныС уязвимости

CVSS3: 7.5
redhat
большС 4 Π»Π΅Ρ‚ Π½Π°Π·Π°Π΄

A flaw was found in grub2 in versions prior to 2.06. The option parser allows an attacker to write past the end of a heap-allocated buffer by calling certain commands with a large number of specific short forms of options. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

CVSS3: 6.7
nvd
большС 4 Π»Π΅Ρ‚ Π½Π°Π·Π°Π΄

A flaw was found in grub2 in versions prior to 2.06. The option parser allows an attacker to write past the end of a heap-allocated buffer by calling certain commands with a large number of specific short forms of options. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

CVSS3: 6.7
msrc
большС 4 Π»Π΅Ρ‚ Π½Π°Π·Π°Π΄

ОписаниС отсутствуСт

CVSS3: 6.7
debian
большС 4 Π»Π΅Ρ‚ Π½Π°Π·Π°Π΄

A flaw was found in grub2 in versions prior to 2.06. The option parser ...

CVSS3: 6.7
github
ΠΎΠΊΠΎΠ»ΠΎ 3 Π»Π΅Ρ‚ Π½Π°Π·Π°Π΄

A flaw was found in grub2 in versions prior to 2.06. The option parser allows an attacker to write past the end of a heap-allocated buffer by calling certain commands with a large number of specific short forms of options. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

EPSS

ΠŸΡ€ΠΎΡ†Π΅Π½Ρ‚ΠΈΠ»ΡŒ: 28%
0.00098
Низкий

7.2 High

CVSS2

6.7 Medium

CVSS3

Π£ΡΠ·Π²ΠΈΠΌΠΎΡΡ‚ΡŒ CVE-2021-20225