Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-12180

Опубликовано: 26 фев. 2019
Источник: redhat
CVSS3: 8.3
EPSS Низкий

Описание

Buffer overflow in BlockIo service for EDK II may allow an unauthenticated user to potentially enable escalation of privilege, information disclosure and/or denial of service via network access.

A flaw was found in edk2. When registering a RAM disk whose size is not a multiple of 512 bytes, the BlockIo protocol produced by the RamDiskDxe driver will incur memory read/write overrun. The memory overrun will happen when reading/writing the last block on the RAM disk. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

Дополнительная информация

Статус:

Important
Дефект:
CWE-125->CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=1683372edk2: Buffer Overflow in BlockIo service for RAM disk

EPSS

Процентиль: 83%
0.02127
Низкий

8.3 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
ubuntu
около 6 лет назад

Buffer overflow in BlockIo service for EDK II may allow an unauthenticated user to potentially enable escalation of privilege, information disclosure and/or denial of service via network access.

CVSS3: 8.8
nvd
около 6 лет назад

Buffer overflow in BlockIo service for EDK II may allow an unauthenticated user to potentially enable escalation of privilege, information disclosure and/or denial of service via network access.

CVSS3: 8.8
debian
около 6 лет назад

Buffer overflow in BlockIo service for EDK II may allow an unauthentic ...

CVSS3: 8.8
github
около 3 лет назад

Buffer overflow in BlockIo service for EDK II may allow an unauthenticated user to potentially enable escalation of privilege, information disclosure and/or denial of service via network access.

oracle-oval
почти 6 лет назад

ELSA-2019-0968: edk2 security update (IMPORTANT)

EPSS

Процентиль: 83%
0.02127
Низкий

8.3 High

CVSS3