Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2020-14309
Description:There's an issue with grub2 in all versions before 2.06 when handling squashfs filesystems containing a symbolic link with name length of UINT32 bytes in size. The name size leads to an arithmetic overflow leading to a zero-size allocation further causing a heap-based buffer overflow with attacker controlled data.
Test IDs: 1.3.6.1.4.1.25623.1.0.704735  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2020-14309
https://security.gentoo.org/glsa/202104-05
https://bugzilla.redhat.com/show_bug.cgi?id=1852022
https://bugzilla.redhat.com/show_bug.cgi?id=1852022
SuSE Security Announcement: openSUSE-SU-2020:1168 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00016.html
SuSE Security Announcement: openSUSE-SU-2020:1169 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00017.html
https://usn.ubuntu.com/4432-1/




© 1998-2025 E-Soft Inc. All rights reserved.