Описание
Insufficient input validation in MdeModulePkg in EDKII may allow an unauthenticated user to potentially enable escalation of privilege, denial of service and/or information disclosure via physical access.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| edk2 | fixed | 2021.02-1 | experimental | package |
| edk2 | fixed | 2020.11-5 | package | |
| edk2 | fixed | 2020.11-2+deb11u1 | bullseye | package |
| edk2 | no-dsa | buster | package | |
| edk2 | no-dsa | stretch | package |
Примечания
https://edk2-docs.gitbook.io/security-advisory/bootguard-toctou-vulnerability
https://bugzilla.tianocore.org/show_bug.cgi?id=1614
https://bugzilla.tianocore.org/attachment.cgi?id=316
Связанные уязвимости
Insufficient input validation in MdeModulePkg in EDKII may allow an unauthenticated user to potentially enable escalation of privilege, denial of service and/or information disclosure via physical access.
Insufficient input validation in MdeModulePkg in EDKII may allow an unauthenticated user to potentially enable escalation of privilege, denial of service and/or information disclosure via physical access.
Insufficient input validation in MdeModulePkg in EDKII may allow an unauthenticated user to potentially enable escalation of privilege, denial of service and/or information disclosure via physical access.