Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2020-14309

There's an issue with grub2 in all versions before 2.06 when handling squashfs filesystems containing a symbolic link with name length of UINT32 bytes in size. The name size leads to an arithmetic overflow leading to a zero-size allocation further causing a heap-based buffer overflow with attacker controlled data.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 14.5%
CVSS Severity
CVSS v3 Score 6.7
CVSS v2 Score 4.6
Products affected by CVE-2020-14309
  • Gnu » Grub2 » Version: N/A
    cpe:2.3:a:gnu:grub2:-
  • Gnu » Grub2 » Version: 1.98
    cpe:2.3:a:gnu:grub2:1.98
  • Gnu » Grub2 » Version: 1.99
    cpe:2.3:a:gnu:grub2:1.99
  • Gnu » Grub2 » Version: 2.00
    cpe:2.3:a:gnu:grub2:2.00
  • Gnu » Grub2 » Version: 2.01
    cpe:2.3:a:gnu:grub2:2.01
  • Gnu » Grub2 » Version: 2.02
    cpe:2.3:a:gnu:grub2:2.02
  • Gnu » Grub2 » Version: 2.04
    cpe:2.3:a:gnu:grub2:2.04
  • Opensuse » Leap » Version: 15.1
    cpe:2.3:o:opensuse:leap:15.1
  • Opensuse » Leap » Version: 15.2
    cpe:2.3:o:opensuse:leap:15.2


Contact Us

Shodan ® - All rights reserved