[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250053

 
 

909

 
 

195940

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS2-2019-1290 --- edk2

ID: oval:org.secpod.oval:def:1700513Date: (C)2020-11-27   (M)2023-11-13
Class: PATCHFamily: unix




Insufficient memory write check in SMM service for EDK II may allow an authenticated user to potentially enable escalation of privilege, information disclosure and/or denial of service via local access. Stack overflow in XHCI for EDK II may allow an unauthenticated user to potentially enable denial of service via local access. Buffer overflows were discovered in UDF-related codes under MdeModulePkg\Universal\Disk\PartitionDxe\Udf.c and MdeModulePkg\Universal\Disk\UdfDxe, which could be triggered with long file names or invalid formatted UDF media. Stack overflow in DxeCore for EDK II may allow an unauthenticated user to potentially enable escalation of privilege, information disclosure and/or denial of service via local access. Improper configuration in system firmware for EDK II may allow unauthenticated user to potentially enable escalation of privilege, information disclosure and/or denial of service via local access

Platform:
Amazon Linux 2
Product:
edk2
Reference:
ALAS2-2019-1290
CVE-2018-12183
CVE-2018-12182
CVE-2019-0160
CVE-2018-12179
CVE-2019-0161
CVE    5
CVE-2018-12183
CVE-2018-12179
CVE-2019-0160
CVE-2019-0161
...
CPE    2
cpe:/a:tianocore:edk2
cpe:/o:amazon:linux:2

© SecPod Technologies