Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2022-28737

Опубликовано: 20 июл. 2023
Источник: debian

Описание

There's a possible overflow in handle_image() when shim tries to load and execute crafted EFI executables; The handle_image() function takes into account the SizeOfRawData field from each section to be loaded. An attacker can leverage this to perform out-of-bound writes into memory. Arbitrary code execution is not discarded in such scenario.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
shimfixed15.6-1package
shimfixed15.6-1~deb11u1bullseyepackage
shimno-dsabusterpackage

Примечания

  • https://www.openwall.com/lists/oss-security/2022/06/07/5

  • https://github.com/rhboot/shim/commit/e99bdbb827a50cde019393d3ca1e89397db221a7 (15.6)

  • https://github.com/rhboot/shim/commit/159151b6649008793d6204a34d7b9c41221fb4b0 (15.6)

Связанные уязвимости

CVSS3: 6.5
ubuntu
почти 2 года назад

There's a possible overflow in handle_image() when shim tries to load and execute crafted EFI executables; The handle_image() function takes into account the SizeOfRawData field from each section to be loaded. An attacker can leverage this to perform out-of-bound writes into memory. Arbitrary code execution is not discarded in such scenario.

CVSS3: 7.3
redhat
около 3 лет назад

There's a possible overflow in handle_image() when shim tries to load and execute crafted EFI executables; The handle_image() function takes into account the SizeOfRawData field from each section to be loaded. An attacker can leverage this to perform out-of-bound writes into memory. Arbitrary code execution is not discarded in such scenario.

CVSS3: 6.5
nvd
почти 2 года назад

There's a possible overflow in handle_image() when shim tries to load and execute crafted EFI executables; The handle_image() function takes into account the SizeOfRawData field from each section to be loaded. An attacker can leverage this to perform out-of-bound writes into memory. Arbitrary code execution is not discarded in such scenario.

CVSS3: 7.8
msrc
7 месяцев назад

Описание отсутствует

suse-cvrf
около 2 лет назад

Security update for shim