Buffer overflow in BlockIo service for EDK II may allow an unauthenticated user to potentially enable escalation of privilege, information disclosure and/or denial of service via network access.
The product writes data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://edk2-docs.gitbooks.io/security-advisory/content/buffer-overflow-in-blockio-service-for-ram-disk.html | patch vendor advisory |
http://lists.opensuse.org/opensuse-security-announce/2019-03/msg00046.html | mailing list third party advisory vendor advisory |
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4ABTDKZK2G5XP6JCO3HXMPOA2NRTIYDZ/ | vendor advisory |
https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03912en_us | |
https://access.redhat.com/errata/RHSA-2019:0809 | vendor advisory |
https://access.redhat.com/errata/RHSA-2019:0968 | vendor advisory |
https://access.redhat.com/errata/RHSA-2019:1116 | vendor advisory |
https://usn.ubuntu.com/4349-1/ | vendor advisory |