漏洞标题
N/A
漏洞描述信息
精心构造的16位灰度 PNG 图像可能导致堆区中的越界写入。攻击者可以利用此漏洞导致堆数据损坏,并最终绕过安全启动保护。解决这个问题的的复杂性很高,因为攻击者需要在堆布局中进行一些筛选,以获得显著的结果,此外,内存中写入的值连续重复三次,这使得生成有效负载变得困难。这个漏洞影响grub2版本在grub-2.12之前。
CVSS信息
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
漏洞类别
N/A
漏洞标题
N/A
漏洞描述信息
A crafted 16-bit grayscale PNG image may lead to a out-of-bounds write in the heap area. An attacker may take advantage of that to cause heap data corruption or eventually arbitrary code execution and circumvent secure boot protections. This issue has a high complexity to be exploited as an attacker needs to perform some triage over the heap layout to achieve signifcant results, also the values written into the memory are repeated three times in a row making difficult to produce valid payloads. This flaw affects grub2 versions prior grub-2.12.
CVSS信息
N/A
漏洞类别
跨界内存写
漏洞标题
grub2 缓冲区错误漏洞
漏洞描述信息
grub2是GNU社区的一款Linux系统引导程序。 grub2 存在缓冲区错误漏洞,攻击者通过精心制作的PNG灰度图像利用该漏洞导致堆中越界写入。
CVSS信息
N/A
漏洞类别
缓冲区错误