First published: Thu Sep 05 2019(Updated: )
Pengutronix barebox through 2019.08.1 has a remote buffer overflow in nfs_readlink_reply in net/nfs.c because a length field is directly used for a memcpy.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Barebox | <=2019.08.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-15937 is classified as a high severity vulnerability due to the potential for remote buffer overflow leading to system compromise.
To fix CVE-2019-15937, update to a version of Barebox that is later than 2019.08.1, as this vulnerability has been addressed in subsequent releases.
CVE-2019-15937 affects versions of Barebox up to and including 2019.08.1 deployed in environments using NFS.
CVE-2019-15937 is a remote buffer overflow vulnerability that can be exploited by an attacker to execute arbitrary code.
CVE-2019-15937 is exploitable in configurations using the network file system (NFS) functionality within the affected Barebox versions.