CVE-2019-15937: Buffer Overflow
Pengutronix barebox through 2019.08.1 has a remote buffer overflow in nfsreadlinkreply in net/nfs.c because a length field is directly used for a memcpy.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2019-15937?
CVE-2019-15937 is classified as a high severity vulnerability due to the potential for remote buffer overflow leading to system compromise.
How do I fix CVE-2019-15937?
To fix CVE-2019-15937, update to a version of Barebox that is later than 2019.08.1, as this vulnerability has been addressed in subsequent releases.
Who is affected by CVE-2019-15937?
CVE-2019-15937 affects versions of Barebox up to and including 2019.08.1 deployed in environments using NFS.
What type of vulnerability is CVE-2019-15937?
CVE-2019-15937 is a remote buffer overflow vulnerability that can be exploited by an attacker to execute arbitrary code.
Is CVE-2019-15937 exploitable in all configurations of Barebox?
CVE-2019-15937 is exploitable in configurations using the network file system (NFS) functionality within the affected Barebox versions.