CVE-2019-13106
Severity CVSS v4.0:
Pending analysis
Type:
CWE-787
Out-of-bounds Write
Publication date:
06/08/2019
Last modified:
03/03/2023
Description
Das U-Boot versions 2016.09 through 2019.07-rc4 can memset() too much data while reading a crafted ext4 filesystem, which results in a stack buffer overflow and likely code execution.
Impact
Base Score 3.x
7.80
Severity 3.x
HIGH
Base Score 2.0
8.30
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:denx:u-boot:*:*:*:*:*:*:*:* | 2016.09 (including) | 2019.04 (including) |
| cpe:2.3:a:denx:u-boot:2019.07:-:*:*:*:*:*:* | ||
| cpe:2.3:a:denx:u-boot:2019.07:rc1:*:*:*:*:*:* | ||
| cpe:2.3:a:denx:u-boot:2019.07:rc2:*:*:*:*:*:* | ||
| cpe:2.3:a:denx:u-boot:2019.07:rc3:*:*:*:*:*:* | ||
| cpe:2.3:a:denx:u-boot:2019.07:rc4:*:*:*:*:*:* | ||
| cpe:2.3:o:opensuse:leap:15.0:*:*:*:*:*:*:* | ||
| cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00002.html
- http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00004.html
- https://gist.github.com/deephooloovoo/d91b81a1674b4750e662dfae93804d75
- https://github.com/u-boot/u-boot/commits/master
- https://lists.denx.de/pipermail/u-boot/2019-July/375516.html



