CVE-2013-3582

Buffer overflow in Dell BIOS on Dell Latitude D###, E####, XT2, and Z600 devices, and Dell Precision M#### devices, allows local users to bypass intended BIOS signing requirements and install arbitrary BIOS images by leveraging administrative privileges and providing a crafted rbu_packet.pktNum value in conjunction with a crafted rbu_packet.pktSize value.
Configurations

Configuration 1 (hide)

OR cpe:2.3:h:dell:latitude_d530:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:latitude_d531:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:latitude_d630:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:latitude_d631:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:latitude_d830:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:latitude_e4200:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:latitude_e4300:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:latitude_e5400:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:latitude_e5500:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:latitude_e6400:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:latitude_e6400_atg:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:latitude_e6400_atg_xfr:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:latitude_e6500:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:latitude_xt2:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:latitude_z600:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:precision_m2300:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:precision_m2400:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:precision_m4300:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:precision_m4400:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:precision_m6300:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:precision_m6400:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:precision_m6500:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2013-08-28 13:13

Updated : 2024-02-04 18:16


NVD link : CVE-2013-3582

Mitre link : CVE-2013-3582

CVE.ORG link : CVE-2013-3582


JSON object : View

Products Affected

dell

  • precision_m6400
  • latitude_d530
  • latitude_d830
  • latitude_e6400_atg
  • precision_m4300
  • latitude_e6500
  • latitude_e6400
  • latitude_z600
  • latitude_d531
  • precision_m4400
  • latitude_e4200
  • latitude_e5400
  • latitude_e6400_atg_xfr
  • precision_m6300
  • precision_m2300
  • precision_m2400
  • latitude_e4300
  • latitude_xt2
  • latitude_e5500
  • latitude_d630
  • precision_m6500
  • latitude_d631
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer