UBUNTU-CVE-2018-3968
Dashboard / Vulnerabilities / UBUNTU-CVE-2018-3968
Summary:
Details: An exploitable vulnerability exists in the verified boot protection of the Das U-Boot from version 2013.07-rc1 to 2014.07-rc2. The affected versions lack proper FIT signature enforcement, which allows an attacker to bypass U-Boot's verified boot and execute an unsigned kernel, embedded in a legacy image format. To trigger this vulnerability, a local attacker needs to be able to supply the image to boot.
References: https://ubuntu.com/security/CVE-2018-3968, https://talosintelligence.com/vulnerability_reports/TALOS-2018-0633, https://www.cve.org/CVERecord?id=CVE-2018-3968
Affected packages
Package
Name: u-boot
Purl: pkg:deb/ubuntu/[email protected]+dfsg-1ubuntu4~18.04.1?arch=source&distro=bionic
Affected ranges
Type: ECOSYSTEM
Events:
