Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2023-45232

Опубликовано: 16 янв. 2024
Источник: debian
EPSS Низкий

Описание

EDK2's Network Package is susceptible to an infinite loop vulnerability when parsing unknown options in the Destination Options header of IPv6. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Availability.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
edk2fixed2023.11-6package
edk2fixed2022.11-6+deb12u1bookwormpackage
edk2no-dsabusterpackage

Примечания

  • https://blog.quarkslab.com/pixiefail-nine-vulnerabilities-in-tianocores-edk-ii-ipv6-network-stack.html

  • https://www.openwall.com/lists/oss-security/2024/01/16/2

EPSS

Процентиль: 49%
0.00255
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 1 года назад

EDK2's Network Package is susceptible to an infinite loop vulnerability when parsing unknown options in the Destination Options header of IPv6. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Availability.

CVSS3: 7.5
redhat
больше 1 года назад

EDK2's Network Package is susceptible to an infinite loop vulnerability when parsing unknown options in the Destination Options header of IPv6. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Availability.

CVSS3: 7.5
nvd
больше 1 года назад

EDK2's Network Package is susceptible to an infinite loop vulnerability when parsing unknown options in the Destination Options header of IPv6. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Availability.

CVSS3: 7.5
msrc
около 1 года назад

Описание отсутствует

CVSS3: 7.5
github
больше 1 года назад

EDK2's Network Package is susceptible to an infinite loop vulnerability when parsing unknown options in the Destination Options header of IPv6. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Availability.

EPSS

Процентиль: 49%
0.00255
Низкий