CVE-2024-42040
8.1
HIGH
CVSS 3.1
EPSS 0.60%
描述
Buffer Overflow vulnerability in the net/bootp.c in DENEX U-Boot from its initial commit in 2002 (3861aa5) up to today on any platform allows an attacker on the local network to leak memory from four up to 32 bytes of memory stored behind the packet to the network depending on the later use of DHCP-provided parameters via crafted DHCP responses.
如何修補 CVE-2024-42040
要修補 CVE-2024-42040,請將受影響套件升級到下列已修補版本。
- Debian/u-boot—升級至 2021.01+dfsg-5+deb11u3 或更新版本
CVE-2024-42040 正在被利用嗎?
低 — EPSS 為 0.6%,目前沒有觀察到大規模利用活動。
受影響套件(1)
- from 0, < 2021.01+dfsg-5+deb11u3
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH8.1 | CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H |