Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-5732

Опубликовано: 16 окт. 2018
Источник: redhat
CVSS3: 6.7

Описание

[REJECTED CVE] A vulnerability exists in EDK-2 within BaseUefiDecompressLib.c (MdePkg/Library/BaseUefiDecompressLib). An authenticated attacker could exploit this vulnerability by supplying a crafted file, potentially leading to privilege escalation.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 8edk2Not affected
Red Hat Enterprise Linux 7ovmfFixedRHSA-2019:212506.08.2019

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-287
https://bugzilla.redhat.com/show_bug.cgi?id=1641446edk2: Privilege escalation via processing of malformed files in BaseUefiDecompressLib.c

6.7 Medium

CVSS3

Связанные уязвимости

ubuntu
больше 5 лет назад

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none.

nvd
больше 5 лет назад

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

suse-cvrf
больше 6 лет назад

Security update for ovmf

suse-cvrf
больше 6 лет назад

Security update for ovmf

suse-cvrf
больше 6 лет назад

Security update for ovmf

6.7 Medium

CVSS3