UBUNTU-CVE-2021-3697
Dashboard / Vulnerabilities / UBUNTU-CVE-2021-3697
UBUNTU-CVE-2021-3697
Summary:
Details: A crafted JPEG image may lead the JPEG reader to underflow its data pointer, allowing user-controlled data to be written in heap. To a successful to be performed the attacker needs to perform some triage over the heap layout and craft an image with a malicious format and payload. This vulnerability can lead to data corruption and eventual code execution or secure boot circumvention. This flaw affects grub2 versions prior grub-2.12.
References: https://ubuntu.com/security/CVE-2021-3697, https://www.openwall.com/lists/oss-security/2022/06/07/5, https://ubuntu.com/security/notices/USN-6355-1, https://www.cve.org/CVERecord?id=CVE-2021-3697
Affected packages
Package
Name: grub2-signed
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=esm-infra-legacy/trusty
Affected ranges
Type: ECOSYSTEM
Events:
