Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-12180

Опубликовано: 27 мар. 2019
Источник: debian
EPSS Низкий

Описание

Buffer overflow in BlockIo service for EDK II may allow an unauthenticated user to potentially enable escalation of privilege, information disclosure and/or denial of service via network access.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
edk2fixed0~20181115.85588389-3package
edk2fixed0~20161202.7bbe0b3e-1+deb9u1stretchpackage
edk2end-of-lifejessiepackage

Примечания

  • https://lists.01.org/pipermail/edk2-devel/2019-February/037248.html

  • https://lists.01.org/pipermail/edk2-devel/2019-February/037249.html

  • https://lists.01.org/pipermail/edk2-devel/2019-February/037250.html

  • https://github.com/tianocore/edk2/commit/38c9fbdcaa0219eb86fe82d90e3f8cfb5a54be9f

  • https://github.com/tianocore/edk2/commit/fccdb88022c1f6d85c773fce506b10c879063f1d

EPSS

Процентиль: 83%
0.02127
Низкий

Связанные уязвимости

CVSS3: 8.8
ubuntu
около 6 лет назад

Buffer overflow in BlockIo service for EDK II may allow an unauthenticated user to potentially enable escalation of privilege, information disclosure and/or denial of service via network access.

CVSS3: 8.3
redhat
больше 6 лет назад

Buffer overflow in BlockIo service for EDK II may allow an unauthenticated user to potentially enable escalation of privilege, information disclosure and/or denial of service via network access.

CVSS3: 8.8
nvd
около 6 лет назад

Buffer overflow in BlockIo service for EDK II may allow an unauthenticated user to potentially enable escalation of privilege, information disclosure and/or denial of service via network access.

CVSS3: 8.8
github
около 3 лет назад

Buffer overflow in BlockIo service for EDK II may allow an unauthenticated user to potentially enable escalation of privilege, information disclosure and/or denial of service via network access.

oracle-oval
почти 6 лет назад

ELSA-2019-0968: edk2 security update (IMPORTANT)

EPSS

Процентиль: 83%
0.02127
Низкий