Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2024-42040

Опубликовано: 23 авг. 2024
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 8.1

Описание

Buffer Overflow vulnerability in the net/bootp.c in DENEX U-Boot from its initial commit in 2002 (3861aa5) up to today on any platform allows an attacker on the local network to leak memory from four up to 32 bytes of memory stored behind the packet to the network depending on the later use of DHCP-provided parameters via crafted DHCP responses.

РелизСтатусПримечание
devel

deferred

esm-infra-legacy/xenial

deferred

esm-infra/bionic

deferred

esm-infra/focal

deferred

esm-infra/xenial

ignored

end of ESM support, was deferred
focal

ignored

end of standard support, was deferred [2025-07-28]
jammy

deferred

noble

deferred

oracular

ignored

end of life, was deferred [2025-07-28]
plucky

ignored

end of life, was deferred

Показывать по

РелизСтатусПримечание
devel

DNE

esm-apps/jammy

deferred

esm-apps/noble

deferred

esm-infra/focal

DNE

focal

DNE

jammy

deferred

noble

deferred

oracular

ignored

end of life, was deferred [2025-07-28]
plucky

ignored

end of life, was deferred
questing

DNE

Показывать по

EPSS

Процентиль: 46%
0.00593
Низкий

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 8.1
nvd
почти 2 года назад

Buffer Overflow vulnerability in the net/bootp.c in DENEX U-Boot from its initial commit in 2002 (3861aa5) up to today on any platform allows an attacker on the local network to leak memory from four up to 32 bytes of memory stored behind the packet to the network depending on the later use of DHCP-provided parameters via crafted DHCP responses.

msrc
6 месяцев назад

Buffer Overflow vulnerability in the net/bootp.c in DENEX U-Boot from its initial commit in 2002 (3861aa5) up to today on any platform allows an attacker on the local network to leak memory from four up to 32 bytes of memory stored behind the packet to the network depending on the later use of DHCP-provided parameters via crafted DHCP responses.

CVSS3: 8.1
debian
почти 2 года назад

Buffer Overflow vulnerability in the net/bootp.c in DENEX U-Boot from ...

CVSS3: 8.1
github
почти 2 года назад

Buffer Overflow vulnerability in the net/bootp.c in DENEX U-Boot from its initial commit in 2002 (3861aa5) up to today on any platform allows an attacker on the local network to leak memory from four up to 32 bytes of memory stored behind the packet to the network depending on the later use of DHCP-provided parameters via crafted DHCP responses.

EPSS

Процентиль: 46%
0.00593
Низкий

8.1 High

CVSS3