PT-2014-1837 · Red Hat+2 · Shim+6
Published
2014-10-22
·
Updated
2024-06-15
·
CVE-2014-3677
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
shim versions 0.7
shim-debuginfo versions 0.7
shim-signed versions 0.7
shim-unsigned versions 0.7
mokutil version 0.7
Description
The issue affects the confidentiality, integrity, and availability of protected information in Red Hat Enterprise Linux. It can be exploited remotely, potentially leading to the execution of arbitrary code via a crafted MOK list, which triggers memory corruption.
Recommendations
For shim version 0.7, consider disabling the vulnerable component until a patch is available.
For shim-debuginfo version 0.7, restrict access to the vulnerable module to minimize the risk of exploitation.
For shim-signed version 0.7, avoid using the crafted MOK list in the affected API endpoint until the issue is resolved.
For shim-unsigned version 0.7, restrict access to the vulnerable module to minimize the risk of exploitation.
For mokutil version 0.7, consider disabling the vulnerable component until a patch is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Red Hat
Suse
Mokutil
Shim
Shim-Debuginfo
Shim-Signed