Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2014-4859

Опубликовано: 31 янв. 2020
Источник: debian

Описание

Integer overflow in the Drive Execution Environment (DXE) phase in the Capsule Update feature in the UEFI implementation in EDK2 allows physically proximate attackers to bypass intended access restrictions via crafted data.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
edk2not-affectedpackage

Примечания

  • https://www.mitre.org/sites/default/files/publications/14-2221-extreme-escalation-presentation.pdf

Связанные уязвимости

CVSS3: 6.8
ubuntu
около 6 лет назад

Integer overflow in the Drive Execution Environment (DXE) phase in the Capsule Update feature in the UEFI implementation in EDK2 allows physically proximate attackers to bypass intended access restrictions via crafted data.

CVSS3: 6.8
nvd
около 6 лет назад

Integer overflow in the Drive Execution Environment (DXE) phase in the Capsule Update feature in the UEFI implementation in EDK2 allows physically proximate attackers to bypass intended access restrictions via crafted data.

github
больше 3 лет назад

Integer overflow in the Drive Execution Environment (DXE) phase in the Capsule Update feature in the UEFI implementation in EDK2 allows physically proximate attackers to bypass intended access restrictions via crafted data.