Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-28734


Out-of-bounds write when handling split HTTP headers; When handling split HTTP headers, GRUB2 HTTP code accidentally moves its internal data buffer point by one position. This can lead to a out-of-bound write further when parsing the HTTP request, writing a NULL byte past the buffer. It's conceivable that an attacker controlled set of packets can lead to corruption of the GRUB2's internal memory metadata.


Published

2023-07-20T01:15:10.243

Last Modified

2024-11-21T06:57:49.817

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 8.1 (HIGH)

Weaknesses
  • Type: Primary
    CWE-787

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application gnu grub2 < 2.06-3 Yes
Application netapp active_iq_unified_manager - Yes

References