CVE-2021-3697 - log back

CVE-2021-3697 edited at 08 Jun 2022 10:16:41
Severity
- Unknown
+ High
Remote
- Unknown
+ Local
Type
- Unknown
+ Arbitrary code execution
Description
+ A crafted JPEG image may lead the JPEG reader to underflow its data pointer, allowing user controlled data to be written in heap. To be successfully performed the attacker needs to do some triage over the heap layout and craft an image with a malicious format and payload. This vulnerability can lead to data corruption and eventual code execution or secure boot circumvention.
References
Notes
CVE-2021-3697 created at 08 Jun 2022 10:10:47