Vulnerability CVE-2022-28734: Information

Description

Out-of-bounds write when handling split HTTP headers; When handling split HTTP headers, GRUB2 HTTP code accidentally moves its internal data buffer point by one position. This can lead to a out-of-bound write further when parsing the HTTP request, writing a NULL byte past the buffer. It's conceivable that an attacker controlled set of packets can lead to corruption of the GRUB2's internal memory metadata.

Severity: HIGH (7.0) Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H

Published: July 20, 2023
Modified: Jan. 16, 2024
Error type identifier: CWE-787

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
grubsisyphus2.06-alt92.06-alt18ALT-PU-2023-1427-1313903Fixed
grubp102.06-alt162.06-alt17ALT-PU-2023-6074-2323459Fixed

References to Advisories, Solutions, and Tools

    1. Configuration 1

      cpe:2.3:a:gnu:grub2:*:*:*:*:*:*:*:*
      Start including
      2.00
      End excliding
      2.06-3

      Configuration 2

      cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:*