CVE-2021-37848
02.08.2021, 20:15
common/password.c in Pengutronix barebox through 2021.07.0 leaks timing information because strncmp is used during hash comparison.Enginsight
Vendor | Product | Version |
---|---|---|
pengutronix | barebox | 𝑥 ≤ 2021.07.0 |
𝑥
= Vulnerable software versions
References