Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
146377 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.1.18.2.2025.0586.1
Categoría:openSUSE Local Security Checks
Título:openSUSE Security Advisory (SUSE-SU-2025:0586-1)
Resumen:The remote host is missing an update for the 'grub2' package(s) announced via the SUSE-SU-2025:0586-1 advisory.
Descripción:Summary:
The remote host is missing an update for the 'grub2' package(s) announced via the SUSE-SU-2025:0586-1 advisory.

Vulnerability Insight:
This update for grub2 fixes the following issues:

- CVE-2024-45781: Fixed strcpy overflow in ufs. (bsc#1233617)
- CVE-2024-56737: Fixed a heap-based buffer overflow in hfs. (bsc#1234958)
- CVE-2024-45782: Fixed strcpy overflow in hfs. (bsc#1233615)
- CVE-2024-45780: Fixed an overflow in tar/cpio. (bsc#1233614)
- CVE-2024-45783: Fixed a refcount overflow in hfsplus. (bsc#1233616)
- CVE-2024-45774: Fixed a heap overflow in JPEG parser. (bsc#1233609)
- CVE-2024-45775: Fixed a missing NULL check in extcmd parser. (bsc#1233610)
- CVE-2024-45776: Fixed an overflow in .MO file handling. (bsc#1233612)
- CVE-2024-45777: Fixed an integer overflow in gettext. (bsc#1233613)
- CVE-2024-45778: Fixed bfs filesystem by removing it from lockdown capable modules. (bsc#1233606)
- CVE-2024-45779: Fixed a heap overflow in bfs. (bsc#1233608)
- CVE-2024-49504: Fixed an issue that can bypass TPM-bound disk encryption on SL(E)M encrypted Images. (bsc#1229164)
- CVE-2025-0624: Fixed an out-of-bounds write during the network boot process. (bsc#1236316)
- CVE-2025-0622: Fixed a use-after-free when handling hooks during module unload in command/gpg . (bsc#1236317)
- CVE-2025-0690: Fixed an integer overflow that may lead to an out-of-bounds write through the read command.
(bsc#1237012)
- CVE-2025-1118: Fixed an issue where the dump command was not being blocked when grub was in lockdown mode.
(bsc#1237013)
- CVE-2025-0677: Fixed an integer overflow that may lead to an out-of-bounds write when handling symlinks in ufs.
(bsc#1237002)
- CVE-2025-0684: Fixed an integer overflow that may lead to an out-of-bounds write when handling symlinks in reiserfs.
(bsc#1237008)
- CVE-2025-0685: Fixed an integer overflow that may lead to an out-of-bounds write when handling symlinks in jfs.
(bsc#1237009)
- CVE-2025-0686: Fixed an integer overflow that may lead to an out-of-bounds write when handling symlinks in romfs.
(bsc#1237010)
- CVE-2025-0689: Fixed a heap-based buffer overflow in udf that may lead to arbitrary code execution. (bsc#1237011)
- CVE-2025-1125: Fixed an integer overflow that may lead to an out-of-bounds write in hfs. (bsc#1237014)
- CVE-2025-0678: Fixed an integer overflow that may lead to an out-of-bounds write in squash4. (bsc#1237006)

Affected Software/OS:
'grub2' package(s) on openSUSE Leap 15.6.

Solution:
Please install the updated package(s).

CVSS Score:
6.8

CVSS Vector:
AV:L/AC:L/Au:S/C:C/I:C/A:C

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2024-45774
Common Vulnerability Exposure (CVE) ID: CVE-2024-45775
Common Vulnerability Exposure (CVE) ID: CVE-2024-45776
Common Vulnerability Exposure (CVE) ID: CVE-2024-45777
Common Vulnerability Exposure (CVE) ID: CVE-2024-45778
Common Vulnerability Exposure (CVE) ID: CVE-2024-45779
Common Vulnerability Exposure (CVE) ID: CVE-2024-45780
Common Vulnerability Exposure (CVE) ID: CVE-2024-45781
Common Vulnerability Exposure (CVE) ID: CVE-2024-45782
Common Vulnerability Exposure (CVE) ID: CVE-2024-45783
Common Vulnerability Exposure (CVE) ID: CVE-2024-49504
Common Vulnerability Exposure (CVE) ID: CVE-2024-56737
Common Vulnerability Exposure (CVE) ID: CVE-2025-0622
Common Vulnerability Exposure (CVE) ID: CVE-2025-0624
Common Vulnerability Exposure (CVE) ID: CVE-2025-0677
Common Vulnerability Exposure (CVE) ID: CVE-2025-0678
Common Vulnerability Exposure (CVE) ID: CVE-2025-0684
Common Vulnerability Exposure (CVE) ID: CVE-2025-0685
Common Vulnerability Exposure (CVE) ID: CVE-2025-0686
Common Vulnerability Exposure (CVE) ID: CVE-2025-0689
Common Vulnerability Exposure (CVE) ID: CVE-2025-0690
Common Vulnerability Exposure (CVE) ID: CVE-2025-1118
Common Vulnerability Exposure (CVE) ID: CVE-2025-1125
CopyrightCopyright (C) 2025 Greenbone AG

Esta es sólo una de 146377 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.