[Forgot Password]
Login  Register Subscribe

30481

 
 

423868

 
 

256288

 
 

909

 
 

199146

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2021-3696Date: (C)2022-06-13   (M)2024-05-10


A heap out-of-bounds write may heppen during the handling of Huffman tables in the PNG reader. This may lead to data corruption in the heap space. Confidentiality, Integrity and Availablity impact may be considered Low as it's very complex to an attacker control the encoding and positioning of corrupted Huffman entries to achieve results such as arbitrary code execution and/or secure boot circumvention. This flaw affects grub2 versions prior grub-2.12.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V3 Severity:CVSS V2 Severity:
CVSS Score : 4.5CVSS Score : 6.9
Exploit Score: 1.0Exploit Score: 3.4
Impact Score: 3.4Impact Score: 10.0
 
CVSS V3 Metrics:CVSS V2 Metrics:
Attack Vector: LOCALAccess Vector: LOCAL
Attack Complexity: HIGHAccess Complexity: MEDIUM
Privileges Required: LOWAuthentication: NONE
User Interaction: NONEConfidentiality: COMPLETE
Scope: UNCHANGEDIntegrity: COMPLETE
Confidentiality: LOWAvailability: COMPLETE
Integrity: LOW 
Availability: LOW 
  
Reference:
GLSA-202209-12
https://bugzilla.redhat.com/show_bug.cgi?id=1991686
https://security.netapp.com/advisory/ntap-20220930-0001/

CWE    1
CWE-787
OVAL    28
oval:org.secpod.oval:def:89046391
oval:org.secpod.oval:def:19500086
oval:org.secpod.oval:def:2600037
oval:org.secpod.oval:def:1505809
...

© SecPod Technologies