Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2023-40547

Опубликовано: 25 янв. 2024
Источник: debian
EPSS Низкий

Описание

A remote code execution vulnerability was found in Shim. The Shim boot support trusts attacker-controlled values when parsing an HTTP response. This flaw allows an attacker to craft a specific malicious HTTP request, leading to a completely controlled out-of-bounds write primitive and complete system compromise. This flaw is only exploitable during the early boot phase, an attacker needs to perform a Man-in-the-Middle or compromise the boot server to be able to exploit this vulnerability successfully.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
shimfixed15.8-1package
shimfixed15.8-1~deb12u1bookwormpackage
shimfixed15.8-1~deb11u1bullseyepackage

Примечания

  • https://bugzilla.redhat.com/show_bug.cgi?id=2234589

  • https://github.com/rhboot/shim/commit/0226b56513b2b8bd5fd281bce77c40c9bf07c66d (15.8)

EPSS

Процентиль: 88%
0.03784
Низкий

Связанные уязвимости

CVSS3: 8.3
ubuntu
больше 1 года назад

A remote code execution vulnerability was found in Shim. The Shim boot support trusts attacker-controlled values when parsing an HTTP response. This flaw allows an attacker to craft a specific malicious HTTP request, leading to a completely controlled out-of-bounds write primitive and complete system compromise. This flaw is only exploitable during the early boot phase, an attacker needs to perform a Man-in-the-Middle or compromise the boot server to be able to exploit this vulnerability successfully.

CVSS3: 8.3
redhat
больше 1 года назад

A remote code execution vulnerability was found in Shim. The Shim boot support trusts attacker-controlled values when parsing an HTTP response. This flaw allows an attacker to craft a specific malicious HTTP request, leading to a completely controlled out-of-bounds write primitive and complete system compromise. This flaw is only exploitable during the early boot phase, an attacker needs to perform a Man-in-the-Middle or compromise the boot server to be able to exploit this vulnerability successfully.

CVSS3: 8.3
nvd
больше 1 года назад

A remote code execution vulnerability was found in Shim. The Shim boot support trusts attacker-controlled values when parsing an HTTP response. This flaw allows an attacker to craft a specific malicious HTTP request, leading to a completely controlled out-of-bounds write primitive and complete system compromise. This flaw is only exploitable during the early boot phase, an attacker needs to perform a Man-in-the-Middle or compromise the boot server to be able to exploit this vulnerability successfully.

CVSS3: 8.3
msrc
около 1 месяца назад

Redhat: CVE-2023-40547 Shim - RCE in HTTP boot support may lead to secure boot bypass

CVSS3: 8.3
github
больше 1 года назад

A remote code execution vulnerability was found in Shim. The Shim boot support trusts attacker-controlled values when parsing an HTTP response. This flaw allows an attacker to craft a specific malicious HTTP request, leading to a completely controlled out-of-bounds write primitive and complete system compromise.

EPSS

Процентиль: 88%
0.03784
Низкий