CVE-2020-19319
published 2023-09-11CVE-2020-19319: Buffer overflow vulnerability in DLINK 619L version B 2.06beta via the FILECODE parameter on login.
PriorityP349critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.77%
51.2th percentile
Buffer overflow vulnerability in DLINK 619L version B 2.06beta via the FILECODE parameter on login.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| dlink | dir-619l_firmware | — | — |
| linux | linux_kernel | >= 0 < 4.4.0-184.214 | 4.4.0-184.214 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-6xjg-4c9c-v748: Buffer overflow vulnerability in DLINK 619L version B 2
ghsa_unreviewed·2023-09-11
CVE-2020-19319 [CRITICAL] CWE-120 GHSA-6xjg-4c9c-v748: Buffer overflow vulnerability in DLINK 619L version B 2
Buffer overflow vulnerability in DLINK 619L version B 2.06beta via the FILECODE parameter on login.
OSV
linux, linux-aws, linux-kvm, linux-raspi2, linux-snapdragon vulnerabilities
osv·2020-06-11·CVSS 6.5
CVE-2019-19319 linux, linux-aws, linux-kvm, linux-raspi2, linux-snapdragon vulnerabilities
linux, linux-aws, linux-kvm, linux-raspi2, linux-snapdragon vulnerabilities
It was discovered that the ext4 file system implementation in the Linux
kernel did not properly handle setxattr operations in some situations. A
local attacker could use this to cause a denial of service (system crash)
or possibly execute arbitrary code. (CVE-2019-19319)
It was discovered that memory contents previously stored in
microarchitectural special registers after RDRAND, RDSEED, and SGX EGETKEY
read operations on Intel client and Xeon E3 processors may be briefly
exposed to processes on the same or different processor cores. A local
attacker could use this to expose sensitive information. (CVE-2020-0543)
Piotr Krysiuk discovered that race conditions existed in the file system
implementation in the Linux
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-09-11
Published