Lucene search

K
rosalinuxROSA LABROSA-SA-2024-2461
HistoryJul 31, 2024 - 9:54 a.m.

Advisory ROSA-SA-2024-2461

2024-07-3109:54:19
ROSA LAB
abf.rosalinux.ru
5
grub2 2.06
rosa-chrome
vulnerability
buffer boundaries
arbitrary code
fixed
sudo dnf update
specially designed font
unicode sequences
insecure temporary file
suse linux enterprise server 15 sp4
opensuse factory
local attackers
prune arbitrary files
sudo dnf update unix

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:L/AC:L/Au:N/C:N/I:P/A:N

CVSS3

8.6

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

AI Score

7.5

Confidence

Low

software: grub2 2.06
WASP: ROSA-CHROME

package_evr_string: grub2-2.06-20

CVE-ID: CVE-2022-2601
BDU-ID: 2022-06819
CVE-Crit: MEDIUM
CVE-DESC.: A vulnerability in the grub_font_construct_glyph() function of the Grub2 operating systems loader is related to an operation exceeding buffer boundaries in memory when processing specially designed fonts in pf2 format. Exploitation of the vulnerability could allow an attacker to execute arbitrary code
CVE-STATUS: Fixed
CVE-REV: To close, run the command: sudo dnf update grub2

CVE-ID: CVE-2021-46705
BDU-ID: None
CVE-Crit: MEDIUM
CVE-DESC.: Insecure Temporary File vulnerability in grub-once grub2 in SUSE Linux Enterprise Server 15 SP4, openSUSE Factory allows local attackers to prune arbitrary files.
CVE-STATUS: Fixed
CVE-REV: To close, run the command: sudo dnf update grub2

CVE-ID: CVE-2022-3775
BDU-ID: 2022-06820
CVE-Crit: MEDIUM
CVE-DESC.: A vulnerability in the Grub2 operating system boot loader is related to an operation exceeding buffer boundaries in memory when rendering certain Unicode sequences in a specially designed font. Exploitation of the vulnerability could allow an attacker to execute arbitrary code
CVE-STATUS: Fixed
CVE-REV: To close, run the command: sudo dnf update grub2

OSVersionArchitecturePackageVersionFilename
ROSAanynoarchgrub2< 2.06UNKNOWN

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:L/AC:L/Au:N/C:N/I:P/A:N

CVSS3

8.6

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

AI Score

7.5

Confidence

Low