Candidate: CVE-2017-9763 PublicDate: 2017-06-19 16:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9763 Description: The grub_ext2_read_block function in fs/ext2.c in GNU GRUB before 2013-11-12, as used in shlr/grub/fs/ext2.c in radare2 1.5.0, allows remote attackers to cause a denial of service (excessive stack use and application crash) via a crafted binary file, related to use of a variable-size stack array. Ubuntu-Description: Notes: Bugs: https://bugs.launchpad.net/ubuntu/+source/radare2/+bug/1882889 https://github.com/radare/radare2/issues/7723 Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H [7.5 HIGH] Patches_grub2: upstream: http://git.savannah.gnu.org/cgit/grub.git/commit/grub-core/fs/ext2.c?id=ac8cac1dac50daaf1c390d701cca3b55e16ee768 Priority_grub2: low upstream_grub2: released (2.02~beta2-8) precise/esm_grub2: ignored (end of ESM support, was needed) trusty_grub2: not-affected (2.02~beta2-9ubuntu1.12) trusty/esm_grub2: not-affected (2.02~beta2-9ubuntu1.12) vivid/ubuntu-core_grub2: ignored (reached end-of-life) xenial_grub2: not-affected (2.02~beta2-36ubuntu3.12) esm-infra/xenial_grub2: not-affected (2.02~beta2-36ubuntu3.12) yakkety_grub2: ignored (reached end-of-life) zesty_grub2: not-affected (2.02~beta3-4ubuntu2.2) artful_grub2: not-affected (2.02~beta3-4ubuntu5) bionic_grub2: not-affected (2.02~beta3-4ubuntu5) cosmic_grub2: not-affected (2.02~beta3-4ubuntu5) disco_grub2: not-affected (2.02~beta3-4ubuntu5) eoan_grub2: not-affected (2.02~beta3-4ubuntu5) focal_grub2: not-affected (2.02~beta3-4ubuntu5) groovy_grub2: not-affected (2.02~beta3-4ubuntu5) hirsute_grub2: not-affected (2.02~beta3-4ubuntu5) impish_grub2: not-affected (2.02~beta3-4ubuntu5) jammy_grub2: not-affected (2.02~beta3-4ubuntu5) devel_grub2: not-affected (2.02~beta3-4ubuntu5) Patches_radare2: upstream: https://github.com/radare/radare2/commit/65000a7fd9eea62359e6d6714f17b94a99a82edd upstream_radare2: released (1.6.0+dfsg-1) precise/esm_radare2: DNE trusty_radare2: ignored (reached end-of-life) trusty/esm_radare2: DNE (trusty was needed) vivid/ubuntu-core_radare2: DNE xenial_radare2: ignored (end of standard support, was needed) yakkety_radare2: ignored (reached end-of-life) zesty_radare2: ignored (reached end-of-life) artful_radare2: ignored (reached end-of-life) bionic_radare2: not-affected (2.3.0+dfsg-2) cosmic_radare2: not-affected (2.3.0+dfsg-2) disco_radare2: not-affected (2.3.0+dfsg-2) eoan_radare2: not-affected (2.3.0+dfsg-2) focal_radare2: not-affected (2.3.0+dfsg-2) groovy_radare2: not-affected (2.3.0+dfsg-2) hirsute_radare2: DNE impish_radare2: DNE jammy_radare2: DNE devel_radare2: DNE