Logo
vulnerabilityCVE-2023-30630
Name
CVE-2023-30630
Source
NVD ( link)Debian ( link)
Description
Dmidecode before 3.5 allows -dump-bin to overwrite a local file. This has security relevance because, for example, execution of Dmidecode via Sudo is plausible. NOTE: Some third parties have indicated the fix in 3.5 does not adequately address the vulnerability. The argument is that the proposed patch prevents dmidecode from writing to an existing file. However, there are multiple attack vectors that would not require overwriting an existing file that would provide the same level of unauthorized privilege escalation (e.g. creating a new file in /etc/cron.hourly).
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
dmidecode
Patched

Vulnerability Ratings#


7.1
CVSSv31
7.1
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
yocto
master
3.7
Not Affected
yocto
scarthgap
3.5
Not Affected

Resolved with patches#


dmidecode (yocto:kirkstone)

#
Title
Author
Resolve
1
dmidecode: Do not let --dump-bin overwrite an existing
Jean Delvare <jdelvare@suse.de>
CVE-2023-30630
2
Consistently use read_file() when reading from a dump
Jean Delvare <jdelvare@suse.de>
CVE-2023-30630
3
dmidecode: Write the whole dump file at once
Jean Delvare <jdelvare@suse.de>
CVE-2023-30630
4
dmidecode: Split table fetching from decoding
Jean Delvare <jdelvare@suse.de>
CVE-2023-30630
5
Don't read beyond sysfs entry point buffer
Jean Delvare <jdelvare@suse.de>
CVE-2023-30630