Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-38796

Опубликовано: 27 сент. 2024
Источник: debian

Описание

EDK2 contains a vulnerability in the PeCoffLoaderRelocateImage(). An Attacker may cause memory corruption due to an overflow via an adjacent network. A successful exploit of this vulnerability may lead to a loss of Confidentiality, Integrity, and/or Availability.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
edk2fixed2024.08-3package
edk2fixed2022.11-6+deb12u2bookwormpackage

Примечания

  • https://github.com/tianocore/edk2/security/advisories/GHSA-xpcr-7hjq-m6qm

  • https://bugzilla.tianocore.org/show_bug.cgi?id=1993

  • https://github.com/tianocore/edk2/pull/6249

  • https://github.com/tianocore/edk2/commit/c95233b8525ca6828921affd1496146cff262e65

Связанные уязвимости

CVSS3: 5.9
ubuntu
9 месяцев назад

EDK2 contains a vulnerability in the PeCoffLoaderRelocateImage(). An Attacker may cause memory corruption due to an overflow via an adjacent network. A successful exploit of this vulnerability may lead to a loss of Confidentiality, Integrity, and/or Availability.

CVSS3: 5.9
redhat
9 месяцев назад

EDK2 contains a vulnerability in the PeCoffLoaderRelocateImage(). An Attacker may cause memory corruption due to an overflow via an adjacent network. A successful exploit of this vulnerability may lead to a loss of Confidentiality, Integrity, and/or Availability.

CVSS3: 5.9
nvd
9 месяцев назад

EDK2 contains a vulnerability in the PeCoffLoaderRelocateImage(). An Attacker may cause memory corruption due to an overflow via an adjacent network. A successful exploit of this vulnerability may lead to a loss of Confidentiality, Integrity, and/or Availability.

CVSS3: 5.9
msrc
30 дней назад

Описание отсутствует

CVSS3: 5.9
redos
8 месяцев назад

Уязвимость edk2-tools