First published: Wed Jul 31 2019(Updated: )
An issue was discovered in Das U-Boot through 2019.07. There is an unbounded memcpy with unvalidated length at nfs_readlink_reply in the "else" block after calculating the new path length.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
DENX U-Boot | <=2019.07 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2019-14195 is critical.
The affected software for CVE-2019-14195 is DENX U-Boot up to and including version 2019.07.
The CWE ID for CVE-2019-14195 is CWE-787.
To fix CVE-2019-14195, it is recommended to update to a version of Das U-Boot after 2019.07.
Yes, there are references available for CVE-2019-14195. You can find them at the following links: [1] https://blog.semmle.com/uboot-rce-nfs-vulnerability/ [2] https://gitlab.com/u-boot/u-boot