Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2022-2347

Опубликовано: 23 сент. 2022
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 7.7

Описание

There exists an unchecked length field in UBoot. The U-Boot DFU implementation does not bound the length field in USB DFU download setup packets, and it does not verify that the transfer direction corresponds to the specified command. Consequently, if a physical attacker crafts a USB DFU download setup packet with a wLength greater than 4096 bytes, they can write beyond the heap-allocated request buffer.

РелизСтатусПримечание
bionic

released

2020.10+dfsg-1ubuntu0~18.04.3
devel

released

2022.07+dfsg-1ubuntu7
esm-infra-legacy/xenial

needs-triage

esm-infra/bionic

released

2020.10+dfsg-1ubuntu0~18.04.3
esm-infra/focal

released

2021.01+dfsg-3ubuntu0~20.04.5
esm-infra/xenial

ignored

end of ESM support, was needs-triage
focal

released

2021.01+dfsg-3ubuntu0~20.04.5
impish

ignored

end of life
jammy

released

2022.01+dfsg-2ubuntu2.3
kinetic

released

2022.07+dfsg-1ubuntu4.2

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-apps/jammy

released

2022.04+git20220405.7446a472-0ubuntu0.4
esm-apps/noble

needed

esm-infra/focal

DNE

focal

DNE

jammy

released

2022.04+git20220405.7446a472-0ubuntu0.4
kinetic

ignored

end of life, was needed
lunar

released

2022.10-1089-g528ae9bc6c-0ubuntu1.23.04.2
mantic

ignored

end of life, was needed

Показывать по

EPSS

Процентиль: 45%
0.00586
Низкий

7.7 High

CVSS3

Связанные уязвимости

CVSS3: 7.7
nvd
почти 4 года назад

There exists an unchecked length field in UBoot. The U-Boot DFU implementation does not bound the length field in USB DFU download setup packets, and it does not verify that the transfer direction corresponds to the specified command. Consequently, if a physical attacker crafts a USB DFU download setup packet with a `wLength` greater than 4096 bytes, they can write beyond the heap-allocated request buffer.

CVSS3: 7.7
debian
почти 4 года назад

There exists an unchecked length field in UBoot. The U-Boot DFU implem ...

CVSS3: 7.1
github
почти 4 года назад

There exists an unchecked length field in UBoot. The U-Boot DFU implementation does not bound the length field in USB DFU download setup packets, and it does not verify that the transfer direction corresponds to the specified command. Consequently, if a physical attacker crafts a USB DFU download setup packet with a `wLength` greater than 4096 bytes, they can write beyond the heap-allocated request buffer.

CVSS3: 7.7
fstec
больше 4 лет назад

Уязвимость компонента drivers/usb/gadget/f_dfu.c загрузчика U-Boot, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании

EPSS

Процентиль: 45%
0.00586
Низкий

7.7 High

CVSS3