Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-5735

Опубликовано: 16 окт. 2018
Источник: redhat
CVSS3: 6.7

Описание

[REJECTED CVE] A heap-based buffer overflow issue was identified in EDK2 in the Decode() function of BaseUefiDecompressLib.c, TianoCompress.c and UEFI Specification. The issue arises from improper handling of data, which could allow an authenticated attacker to exploit it by supplying a crafted file. This could lead to privilege escalation.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 8edk2Not affected
Red Hat Enterprise Linux 7ovmfFixedRHSA-2019:212506.08.2019

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-287
https://bugzilla.redhat.com/show_bug.cgi?id=1641465edk2: Privilege escalation via heap-based buffer overflow in Decode() function

6.7 Medium

CVSS3

Связанные уязвимости

ubuntu
больше 5 лет назад

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none.

nvd
больше 5 лет назад

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

suse-cvrf
больше 6 лет назад

Security update for ovmf

suse-cvrf
больше 6 лет назад

Security update for ovmf

suse-cvrf
больше 6 лет назад

Security update for ovmf

6.7 Medium

CVSS3