Integer Overflow Vulnerability in ARM Trusted Firmware by ARM Holdings
CVE-2016-10319
5.9MEDIUM
Key Information:
- Vendor
- Arm Trusted Firmware Project
- Status
- Arm Trusted Firmware
- Vendor
- CVE Published:
- 6 April 2017
Summary
In versions 1.2 and 1.3 of ARM Trusted Firmware, a vulnerability exists that allows a malformed firmware update SMC to cause integer overflows. This can result in unexpectedly large data being copied into secure memory, which may compromise system integrity. The vulnerability primarily affects scenarios involving the execution of AArch64 Generic Trusted Firmware (TF) BL1 code along with other firmware update operations.
References
CVSS V3.1
Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability Reserved
Vulnerability published