CVE-2022-28733 - CERT CVE
ID CVE-2022-28733
Sažetak Integer underflow in grub_net_recv_ip4_packets; A malicious crafted IP packet can lead to an integer underflow in grub_net_recv_ip4_packets() function on rsm->total_len value. Under certain circumstances the total_len value may end up wrapping around to a small integer number which will be used in memory allocation. If the attack succeeds in such way, subsequent operations can write past the end of the buffer.
Reference
CVSS
Base: 8.1
Impact: 5.9
Exploitability:2.2
Pristup
VektorSloženostAutentikacija
NETWORK HIGH -
Impact
PovjerljivostCjelovitostDostupnost
HIGH HIGH HIGH
CVSS vektor CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Zadnje važnije ažuriranje 25-08-2023 - 23:15
Objavljeno 20-07-2023 - 01:15