Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2014-4859

Опубликовано: 31 янв. 2020
Источник: debian
EPSS Низкий

Описание

Integer overflow in the Drive Execution Environment (DXE) phase in the Capsule Update feature in the UEFI implementation in EDK2 allows physically proximate attackers to bypass intended access restrictions via crafted data.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
edk2not-affectedpackage

Примечания

  • https://www.mitre.org/sites/default/files/publications/14-2221-extreme-escalation-presentation.pdf

EPSS

Процентиль: 45%
0.00587
Низкий

Связанные уязвимости

CVSS3: 6.8
ubuntu
больше 6 лет назад

Integer overflow in the Drive Execution Environment (DXE) phase in the Capsule Update feature in the UEFI implementation in EDK2 allows physically proximate attackers to bypass intended access restrictions via crafted data.

CVSS3: 6.8
nvd
больше 6 лет назад

Integer overflow in the Drive Execution Environment (DXE) phase in the Capsule Update feature in the UEFI implementation in EDK2 allows physically proximate attackers to bypass intended access restrictions via crafted data.

github
больше 4 лет назад

Integer overflow in the Drive Execution Environment (DXE) phase in the Capsule Update feature in the UEFI implementation in EDK2 allows physically proximate attackers to bypass intended access restrictions via crafted data.

EPSS

Процентиль: 45%
0.00587
Низкий