DENX U-Boot through 2018.09-rc1 has a remotely...
Critical severity
Unreviewed
Published
May 14, 2022
to the GitHub Advisory Database
•
Updated Jan 23, 2023
Description
Published by the National Vulnerability Database
Nov 20, 2018
Published to the GitHub Advisory Database
May 14, 2022
Last updated
Jan 23, 2023
DENX U-Boot through 2018.09-rc1 has a remotely exploitable buffer overflow via a malicious TFTP server because TFTP traffic is mishandled. Also, local exploitation can occur via a crafted kernel image.
References