CVE-2020-0256
説明
An out-of-bounds write flaw was found in gdisks' LoadPartitionTable() function of 'gpt.cc'. The exploitation of this flaw requires the use of a malicious storage device (for example, a USB Stick) that can cause a crash when physically inserted into the system and possible local privilege escalation. This flaw allows an attacker to compromise confidentiality, integrity, and data availability.
詳細
This vulnerability does affect Red Hat Enterprise Linux 6, 7, and 8 because our code-base is vulnerable to this issue.
Red Hat Product Security has rated this issue as a Moderate security impact and the issue is not currently planned to be addressed in future updates for Red Hat Enterprise Linux 6 and 7, hence, marked as Out-of-Support-Scope. For additional information, refer to the Red Hat Enterprise Linux Life Cycle & Update Policy: https://access.redhat.com/support/policy/updates/errata/.
CVSS (Common Vulnerability Scoring System) のスコアの詳細
Info alert:Important note
CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).
CVSS v3 スコアの内訳
| Red Hat | NVD | cve.org | |
|---|---|---|---|
| ベーススコア | 6.8 | 6.8 | N/A |
| 攻撃ベクトル | Physical | Physical | N/A |
| 攻撃の複雑さ | Low | Low | N/A |
| 必要な権限 | None | None | N/A |
| ユーザー関与レベル | None | None | N/A |
| 範囲 | Unchanged | Unchanged | N/A |
| 機密性 | High | High | N/A |
| 完全性への影響 | High | High | N/A |
| 可用性への影響 | High | High | N/A |
ベクトル
Red Hat: CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
NVD: CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
脆弱性の原因 (CWE) の理解
Integrity
Technical Impact: Modify Memory; Execute Unauthorized Code or Commands
Write operations could cause memory corruption. In some cases, an adversary can modify control data such as return addresses in order to execute unexpected code.
Availability
Technical Impact: DoS: Crash, Exit, or Restart
Attempting to access out-of-range, invalid, or unauthorized memory could cause the product to crash.
Other
Technical Impact: Unexpected State
Subsequent write operations can produce undefined or unexpected results.
よくある質問
Not sure what something means? Check out our Security Glossary.
エラータ通知の受信を希望しますか? こちらで登録してください。