Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2021-3695

Опубликовано: 06 июл. 2022
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 4.4
CVSS3: 4.5

Описание

A crafted 16-bit grayscale PNG image may lead to a out-of-bounds write in the heap area. An attacker may take advantage of that to cause heap data corruption or eventually arbitrary code execution and circumvent secure boot protections. This issue has a high complexity to be exploited as an attacker needs to perform some triage over the heap layout to achieve signifcant results, also the values written into the memory are repeated three times in a row making difficult to produce valid payloads. This flaw affects grub2 versions prior grub-2.12.

РелизСтатусПримечание
bionic

ignored

end of standard support, was needed
devel

not-affected

does not affect Secure Boot
esm-infra-legacy/trusty

not-affected

does not affect Secure Boot
esm-infra/bionic

not-affected

does not affect Secure Boot
esm-infra/focal

not-affected

does not affect Secure Boot
esm-infra/xenial

not-affected

does not affect Secure Boot
focal

not-affected

does not affect Secure Boot
impish

ignored

end of life
jammy

not-affected

does not affect Secure Boot
kinetic

not-affected

does not affect Secure Boot

Показывать по

РелизСтатусПримечание
bionic

released

1.187.3~18.04.1
devel

not-affected

1.193
esm-infra-legacy/trusty

needed

esm-infra/bionic

not-affected

1.187.3~18.04.1
esm-infra/focal

not-affected

1.187.3~20.04.1
esm-infra/xenial

needed

focal

released

1.187.3~20.04.1
jammy

released

1.187.3~22.04.1
kinetic

ignored

end of life
lunar

not-affected

1.192

Показывать по

РелизСтатусПримечание
bionic

released

2.06-2ubuntu14.1
devel

not-affected

2.06-2ubuntu17
esm-infra-legacy/trusty

DNE

esm-infra/bionic

not-affected

2.06-2ubuntu14.1
esm-infra/focal

not-affected

2.06-2ubuntu14.1
esm-infra/xenial

needed

focal

released

2.06-2ubuntu14.1
jammy

released

2.06-2ubuntu14.1
kinetic

ignored

end of life
lunar

not-affected

2.06-2ubuntu16

Показывать по

EPSS

Процентиль: 16%
0.00051
Низкий

4.4 Medium

CVSS2

4.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
redhat
около 3 лет назад

A crafted 16-bit grayscale PNG image may lead to a out-of-bounds write in the heap area. An attacker may take advantage of that to cause heap data corruption or eventually arbitrary code execution and circumvent secure boot protections. This issue has a high complexity to be exploited as an attacker needs to perform some triage over the heap layout to achieve signifcant results, also the values written into the memory are repeated three times in a row making difficult to produce valid payloads. This flaw affects grub2 versions prior grub-2.12.

CVSS3: 4.5
nvd
почти 3 года назад

A crafted 16-bit grayscale PNG image may lead to a out-of-bounds write in the heap area. An attacker may take advantage of that to cause heap data corruption or eventually arbitrary code execution and circumvent secure boot protections. This issue has a high complexity to be exploited as an attacker needs to perform some triage over the heap layout to achieve signifcant results, also the values written into the memory are repeated three times in a row making difficult to produce valid payloads. This flaw affects grub2 versions prior grub-2.12.

CVSS3: 4.5
msrc
больше 1 года назад

Описание отсутствует

CVSS3: 4.5
debian
почти 3 года назад

A crafted 16-bit grayscale PNG image may lead to a out-of-bounds write ...

CVSS3: 4.5
github
почти 3 года назад

A crafted 16-bit grayscale PNG image may lead to a out-of-bounds write in the heap area. An attacker may take advantage of that to cause heap data corruption or eventually arbitrary code execution and circumvent secure boot protections. This issue has a high complexity to be exploited as an attacker needs to perform some triage over the heap layout to achieve signifcant results, also the values written into the memory are repeated three times in a row making difficult to produce valid payloads. This flaw affects grub2 versions prior grub-2.12.

EPSS

Процентиль: 16%
0.00051
Низкий

4.4 Medium

CVSS2

4.5 Medium

CVSS3