OESA-2022-1800
Dashboard / Vulnerabilities / OESA-2022-1800
Summary: uboot-tools security update
Details: This package includes the mkimage program, which allows generation of U-Boot images in various formats, and the fw_printenv and fw_setenv programs to read and modify U-Boot's environment. Security Fix(es): squashfs filesystem implementation of U-Boot versions from v2020.10-rc2 to v2022.07-rc5 contains a heap-based buffer overflow vulnerability due to a defect in the metadata reading process. Loading a specially crafted squashfs image may lead to a denial-of-service (DoS) condition or arbitrary code execution.(CVE-2022-33967)
References: https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2022-1800, https://nvd.nist.gov/vuln/detail/CVE-2022-33967
Affected packages
Package
Name: uboot-tools
Purl: pkg:rpm/openEuler/uboot-tools&distro=openEuler-22.03-LTS
Affected ranges
Type: ECOSYSTEM
Events:
