Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-12178

Опубликовано: 26 фев. 2019
Источник: redhat
CVSS3: 7.2
EPSS Низкий

Описание

Buffer overflow in network stack for EDK II may allow unprivileged user to potentially enable escalation of privilege and/or denial of service via network.

A missing check leads to an out-of-bounds read and write flaw in NetworkPkg/DnsDxe as shipped in edk2, when it parses DNS responses. A remote attacker who controls the DNS server used by the vulnerable firmware may use this flaw to make the system crash.

Отчет

This issue did not affect the versions of OVMF as shipped with Red Hat Enterprise Linux 7 as they were not compiled with HTTP_BOOT_ENABLE set, thus they do not contain the vulnerable code.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7OVMFNot affected
Red Hat Enterprise Linux 8edk2Not affected
Red Hat Virtualization 4redhat-virtualization-hostNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-125->CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=1683326edk2: improper DNS packet size check

EPSS

Процентиль: 69%
0.0061
Низкий

7.2 High

CVSS3

Связанные уязвимости

CVSS3: 9.1
ubuntu
около 6 лет назад

Buffer overflow in network stack for EDK II may allow unprivileged user to potentially enable escalation of privilege and/or denial of service via network.

CVSS3: 9.1
nvd
около 6 лет назад

Buffer overflow in network stack for EDK II may allow unprivileged user to potentially enable escalation of privilege and/or denial of service via network.

CVSS3: 9.1
debian
около 6 лет назад

Buffer overflow in network stack for EDK II may allow unprivileged use ...

CVSS3: 9.1
github
около 3 лет назад

Buffer overflow in network stack for EDK II may allow unprivileged user to potentially enable escalation of privilege and/or denial of service via network.

CVSS3: 7.2
fstec
почти 7 лет назад

Уязвимость библиотеки Tianocore edk2, вызванная недостаточной проверкой вводимых пользователем данных, позволяющая нарушителю повысить свои привилегии или вызвать отказ в обслуживании

EPSS

Процентиль: 69%
0.0061
Низкий

7.2 High

CVSS3