Skip to content

WS-2018-0604 (High) detected in ubootrelease-20161011 #15

@mend-bolt-for-github

Description

@mend-bolt-for-github

WS-2018-0604 - High Severity Vulnerability

Vulnerable Library - ubootrelease-20161011

Library home page: https://github.com/nono5/uboot.git

Found in HEAD commit: e003f8ec3a51e24e565b17a8e75e5398d5717863

Vulnerable Source Files (3)

/drivers/net/fsl-mc/mc.c
/drivers/net/ldpaa_eth/ldpaa_eth.c
/drivers/net/fsl-mc/mc.c

Vulnerability Details

U-Boot before v2018.09-rc2 is vulnerable to a buffer overflow which can lead to a potential code execution.

Publish Date: 2018-08-02

URL: WS-2018-0604

CVSS 3 Score Details (7.3)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: Low
    • Integrity Impact: Low
    • Availability Impact: Low

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2018-08-02

Fix Resolution: v2018.09


Step up your Open Source Security Game with Mend here

Metadata

Metadata

Assignees

No one assigned

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions