Buffer Overflow vulnerability in the net/bootp.c in DENEX U-Boot from its initial commit in 2002 (3861aa5) up to today on any platform allows an attacker on the local network to leak memory from four up to 32 bytes of memory stored behind the packet to the network depending on the later use of DHCP-provided parameters via crafted DHCP responses.
History

Fri, 22 Nov 2024 12:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-120
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H'}


Mon, 26 Aug 2024 20:30:00 +0000

Type Values Removed Values Added
References
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 26 Aug 2024 17:30:00 +0000

Type Values Removed Values Added
References

Fri, 23 Aug 2024 14:30:00 +0000

Type Values Removed Values Added
Description Buffer Overflow vulnerability in the net/bootp.c in DENEX U-Boot from its initial commit in 2002 (3861aa5) up to today on any platform allows an attacker on the local network to leak memory from four up to 32 bytes of memory stored behind the packet to the network depending on the later use of DHCP-provided parameters via crafted DHCP responses.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2024-08-23T00:00:00

Updated: 2024-11-20T16:22:55.745Z

Reserved: 2024-07-27T00:00:00

Link: CVE-2024-42040

cve-icon Vulnrichment

Updated: 2024-08-26T17:09:36.109Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-08-23T15:15:16.323

Modified: 2024-11-21T09:33:28.207

Link: CVE-2024-42040

cve-icon Redhat

No data.