Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2022-28737

Опубликовано: 20 июл. 2023
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 6.5

Описание

There's a possible overflow in handle_image() when shim tries to load and execute crafted EFI executables; The handle_image() function takes into account the SizeOfRawData field from each section to be loaded. An attacker can leverage this to perform out-of-bound writes into memory. Arbitrary code execution is not discarded in such scenario.

РелизСтатусПримечание
bionic

ignored

end of standard support, was needed
devel

not-affected

15.7-0ubuntu1
esm-infra-legacy/trusty

ignored

install media keys will never be revoked
esm-infra/bionic

pending

15.7-0ubuntu1
esm-infra/focal

not-affected

15.7-0ubuntu1
esm-infra/xenial

ignored

install media keys will never be revoked
focal

released

15.7-0ubuntu1
impish

ignored

end of life
jammy

released

15.7-0ubuntu1
kinetic

ignored

end of life, was needed

Показывать по

EPSS

Процентиль: 4%
0.00021
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.3
redhat
около 3 лет назад

There's a possible overflow in handle_image() when shim tries to load and execute crafted EFI executables; The handle_image() function takes into account the SizeOfRawData field from each section to be loaded. An attacker can leverage this to perform out-of-bound writes into memory. Arbitrary code execution is not discarded in such scenario.

CVSS3: 6.5
nvd
почти 2 года назад

There's a possible overflow in handle_image() when shim tries to load and execute crafted EFI executables; The handle_image() function takes into account the SizeOfRawData field from each section to be loaded. An attacker can leverage this to perform out-of-bound writes into memory. Arbitrary code execution is not discarded in such scenario.

CVSS3: 7.8
msrc
7 месяцев назад

Описание отсутствует

CVSS3: 6.5
debian
почти 2 года назад

There's a possible overflow in handle_image() when shim tries to load ...

suse-cvrf
около 2 лет назад

Security update for shim

EPSS

Процентиль: 4%
0.00021
Низкий

6.5 Medium

CVSS3