SB2018062622 - Input validation error in DENX U-Boot



SB2018062622 - Input validation error in DENX U-Boot

Published: June 26, 2018 Updated: August 8, 2020

Security Bulletin ID SB2018062622
Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Input validation error (CVE-ID: CVE-2018-1000205)

The vulnerability allows a remote non-authenticated attacker to manipulate data.

U-Boot contains a CWE-20: Improper Input Validation vulnerability in Verified boot signature validation that can result in Bypass verified boot. This attack appear to be exploitable via Specially crafted FIT image and special device memory functionality.


Remediation

Install update from vendor's website.