CVE-2019-14192 PUBLISHED

An issue was discovered in Das U-Boot through 2019.07. There is an unbounded memcpy when parsing a UDP packet due to a net_process_received_packet integer underflow during an nc_input_packet call.

EPSS 0.54% · 67.5th percentile

Risk Scores

EPSS Score
0.54%
67.5th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSu-boot0, 2015.04+dfsg1-2ubuntu1, 2015.10+dfsg1-2
Ubuntu:18.04:LTSu-boot0, 2016.03+dfsg1-6ubuntu2, 2018.07~rc3+dfsg1-0ubuntu1~18.04.1
Ubuntu:20.04:LTSu-boot0, 2019.07+dfsg-1ubuntu3, 2019.07+dfsg-1ubuntu5

Timeline

References

Open in Interactive Console →