CVE-2023-45840
05.12.2023, 12:15
Multiple data integrity vulnerabilities exist in the package hash checking functionality of Buildroot 2023.08.1 and Buildroot dev commit 622698d7847. A specially crafted man-in-the-middle attack can lead to arbitrary command execution in the builder.This vulnerability is related to the `riscv64-elf-toolchain` package.Enginsight
Vendor | Product | Version |
---|---|---|
buildroot | buildroot | 2023.08.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration