IM
IronMonkey Threat Research

CVE-2019-13106 HIGH

Published: 2019-08-06 | Last Modified: 2026-05-12 | Status: Modified

Description

Das U-Boot versions 2016.09 through 2019.07-rc4 can memset() too much data while reading a crafted ext4 filesystem, which results in a stack buffer overflow and likely code execution.

Additional Descriptions (1)

Das U-Boot versiones 2016.09 hasta 2019.07-rc4, pueden memorizar en la función memset() muchos datos mientras leen un sistema de archivos ext4 diseñado, lo que resulta en un desbordamiento del búfer de la pila y una posible ejecución de código.

CVSS Metrics

Base Score: 7.8 (HIGH)

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Attack VectorLOCAL
Attack ComplexityLOW
Privileges RequiredNONE
User InteractionREQUIRED
ScopeUNCHANGED
Confidentiality ImpactHIGH
Integrity ImpactHIGH
Availability ImpactHIGH

Source: [email protected]

Type: Primary

Exploitability Score: 1.8

Impact Score: 5.9

Base Score: 8.3 (HIGH)

AV:N/AC:M/Au:N/C:P/I:P/A:C

Access VectorNETWORK
Access ComplexityMEDIUM
AuthenticationNONE
Confidentiality ImpactPARTIAL
Integrity ImpactPARTIAL
Availability ImpactCOMPLETE

Source: [email protected]

Type: Primary

Exploitability Score: 8.6

Impact Score: 8.5

Weaknesses

Source Type Description
[email protected] Primary
en CWE-787

Affected Products

Vendor Product Version Update Type
denx u-boot * <built-in method update of dict object at 0x7b06fd60be80> Application
denx u-boot 2019.07 <built-in method update of dict object at 0x7b06ea0ef2c0> Application
denx u-boot 2019.07 <built-in method update of dict object at 0x7b070cc2ae40> Application
denx u-boot 2019.07 <built-in method update of dict object at 0x7b06bed31a00> Application
denx u-boot 2019.07 <built-in method update of dict object at 0x7b06fd60aec0> Application
denx u-boot 2019.07 <built-in method update of dict object at 0x7b06fd60a200> Application
opensuse leap 15.0 <built-in method update of dict object at 0x7b06ea0ed100> Operating System
opensuse leap 15.1 <built-in method update of dict object at 0x7b06bed33c00> Operating System

Affected Configurations

Operator: OR

Vulnerable CPE
Yes cpe:2.3:a:denx:u-boot:*:*:*:*:*:*:*:*
Yes cpe:2.3:a:denx:u-boot:2019.07:-:*:*:*:*:*:*
Yes cpe:2.3:a:denx:u-boot:2019.07:rc1:*:*:*:*:*:*
Yes cpe:2.3:a:denx:u-boot:2019.07:rc2:*:*:*:*:*:*
Yes cpe:2.3:a:denx:u-boot:2019.07:rc3:*:*:*:*:*:*
Yes cpe:2.3:a:denx:u-boot:2019.07:rc4:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:opensuse:leap:15.0:*:*:*:*:*:*:*
Yes cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:*
Notification
Message here