First published: Mon Jul 29 2019(Updated: )
A crafted self-referential DOS partition table will cause all Das U-Boot versions through 2019.07-rc4 to infinitely recurse, causing the stack to grow infinitely and eventually either crash or overwrite other data.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
DENX U-Boot | <2019.04 | |
DENX U-Boot | =2019.04 | |
DENX U-Boot | =2019.04-rc1 | |
DENX U-Boot | =2019.04-rc2 | |
DENX U-Boot | =2019.04-rc3 | |
DENX U-Boot | =2019.04-rc4 | |
DENX U-Boot | =2019.07-rc1 | |
DENX U-Boot | =2019.07-rc2 | |
DENX U-Boot | =2019.07-rc3 | |
DENX U-Boot | =2019.07-rc4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-13103 is a vulnerability in Das U-Boot versions through 2019.07-rc4 that allows a crafted self-referential DOS partition table to cause infinite recursion, leading to a stack overflow or data overwrite.
CVE-2019-13103 affects DENX U-Boot versions 2019.04 to 2019.07-rc4, causing potential crashes or data corruption.
CVE-2019-13103 has a severity rating of 7.1 (High).
To fix CVE-2019-13103, it is recommended to upgrade to a fixed version of Das U-Boot, such as version 2019.07 or later.
More information about CVE-2019-13103 can be found at the following references: [Link 1](https://cert-portal.siemens.com/productcert/pdf/ssa-618620.pdf), [Link 2](https://gist.github.com/deephooloovoo/d91b81a1674b4750e662dfae93804d75), [Link 3](https://github.com/u-boot/u-boot/commits/master).