A data integrity vulnerability exists in the...
High severity
Unreviewed
Published
Dec 5, 2023
to the GitHub Advisory Database
•
Updated Dec 11, 2023
Description
Published by the National Vulnerability Database
Dec 5, 2023
Published to the GitHub Advisory Database
Dec 5, 2023
Last updated
Dec 11, 2023
A data integrity vulnerability exists in the BR_NO_CHECK_HASH_FOR functionality of Buildroot 2023.08.1 and dev commit 622698d7847. A specially crafted man-in-the-middle attack can lead to arbitrary command execution in the builder.
References