CVE-2019-13104
Severity CVSS v4.0:
Pending analysis
Type:
CWE-191
Integer Underflow (Wrap or Wraparound)
Publication date:
06/08/2019
Last modified:
18/04/2022
Description
In Das U-Boot versions 2016.11-rc1 through 2019.07-rc4, an underflow can cause memcpy() to overwrite a very large amount of data (including the whole stack) while reading a crafted ext4 filesystem.
Impact
Base Score 3.x
7.80
Severity 3.x
HIGH
Base Score 2.0
6.80
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:denx:u-boot:*:*:*:*:*:*:*:* | 2016.09 (including) | 2019.04 (including) |
cpe:2.3:a:denx:u-boot:2019.07:-:*:*:*:*:*:* | ||
cpe:2.3:a:denx:u-boot:2019.07:rc1:*:*:*:*:*:* | ||
cpe:2.3:a:denx:u-boot:2019.07:rc2:*:*:*:*:*:* | ||
cpe:2.3:a:denx:u-boot:2019.07:rc3:*:*:*:*:*:* | ||
cpe:2.3:a:denx:u-boot:2019.07:rc4:*:*:*:*:*:* | ||
cpe:2.3:o:opensuse:leap:15.0:*:*:*:*:*:*:* | ||
cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00002.html
- http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00004.html
- https://gist.github.com/deephooloovoo/d91b81a1674b4750e662dfae93804d75
- https://github.com/u-boot/u-boot/commits/master
- https://lists.denx.de/pipermail/u-boot/2019-July/375514.html