mirror of
https://github.com/0xMarcio/cve.git
synced 2025-05-08 03:26:30 +00:00
41 lines
2.0 KiB
Markdown
41 lines
2.0 KiB
Markdown
![]() |
### [CVE-2020-14310](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-14310)
|
||
|

|
||
|

|
||
|

|
||
|

|
||
|
|
||
|
### Description
|
||
|
|
||
|
There is an issue on grub2 before version 2.06 at function read_section_as_string(). It expects a font name to be at max UINT32_MAX - 1 length in bytes but it doesn't verify it before proceed with buffer allocation to read the value from the font value. An attacker may leverage that by crafting a malicious font file which has a name with UINT32_MAX, leading to read_section_as_string() to an arithmetic overflow, zero-sized allocation and further heap-based buffer overflow.
|
||
|
|
||
|
### POC
|
||
|
|
||
|
#### Reference
|
||
|
No PoCs from references.
|
||
|
|
||
|
#### Github
|
||
|
- https://github.com/ARPSyndicate/cvemon
|
||
|
- https://github.com/DNTYO/F5_Vulnerability
|
||
|
- https://github.com/EuroLinux/shim-review
|
||
|
- https://github.com/Jurij-Ivastsuk/WAXAR-shim-review
|
||
|
- https://github.com/NaverCloudPlatform/shim-review
|
||
|
- https://github.com/Rodrigo-NR/shim-review
|
||
|
- https://github.com/amzdev0401/shim-review-backup
|
||
|
- https://github.com/bitraser/shim-review-15.4
|
||
|
- https://github.com/coreyvelan/shim-review
|
||
|
- https://github.com/ctrliq/ciq-shim-build
|
||
|
- https://github.com/ctrliq/shim-review
|
||
|
- https://github.com/jason-chang-atrust/shim-review
|
||
|
- https://github.com/lenovo-lux/shim-review
|
||
|
- https://github.com/luojc123/shim-nsdl
|
||
|
- https://github.com/mwti/rescueshim
|
||
|
- https://github.com/neppe/shim-review
|
||
|
- https://github.com/neverware/shim-review
|
||
|
- https://github.com/ozun215/shim-review
|
||
|
- https://github.com/puzzleos/uefi-shim_review
|
||
|
- https://github.com/renorobert/grub-bhyve-bugs
|
||
|
- https://github.com/rhboot/shim-review
|
||
|
- https://github.com/synackcyber/BootHole_Fix
|
||
|
- https://github.com/vathpela/shim-review
|
||
|
|