Integer Overflow Vulnerability in ARM Trusted Firmware by ARM Holdings
CVE-2016-10319

5.9MEDIUM

Key Information:

Vendor
Arm Trusted Firmware Project
Status
Arm Trusted Firmware
Vendor
CVE Published:
6 April 2017

Summary

In versions 1.2 and 1.3 of ARM Trusted Firmware, a vulnerability exists that allows a malformed firmware update SMC to cause integer overflows. This can result in unexpectedly large data being copied into secure memory, which may compromise system integrity. The vulnerability primarily affects scenarios involving the execution of AArch64 Generic Trusted Firmware (TF) BL1 code along with other firmware update operations.

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.