CVE-2019-11690

Severity CVSS v4.0:
Pending analysis
Type:
CWE-330 Use of Insufficiently Random Value
Publication date:
03/05/2019
Last modified:
06/05/2019

Description

gen_rand_uuid in lib/uuid.c in Das U-Boot v2014.04 through v2019.04 lacks an srand call, which allows attackers to determine UUID values in scenarios where CONFIG_RANDOM_UUID is enabled, and Das U-Boot is relied upon for UUID values of a GUID Partition Table of a boot device.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:denx:u-boot:*:*:*:*:*:*:*:* 2014.04 (including) 2019.04 (including)


References to Advisories, Solutions, and Tools