Lucene search

K
prionPRIOn knowledge basePRION:CVE-2022-28734
HistoryJul 20, 2023 - 1:15 a.m.

Design/Logic Flaw

2023-07-2001:15:00
PRIOn knowledge base
www.prio-n.com
10
design flaw
logic flaw
http headers
grub2
out-of-bounds write
memory corruption

9.4 High

AI Score

Confidence

High

0.0005 Low

EPSS

Percentile

17.0%

Out-of-bounds write when handling split HTTP headers; When handling split HTTP headers, GRUB2 HTTP code accidentally moves its internal data buffer point by one position. This can lead to a out-of-bound write further when parsing the HTTP request, writing a NULL byte past the buffer. It’s conceivable that an attacker controlled set of packets can lead to corruption of the GRUB2’s internal memory metadata.

CPENameOperatorVersion
grub2ge2.00
grub2lt2.06