PT-2014-1837 · Red Hat+2 · Shim+6

Published

2014-10-22

·

Updated

2024-06-15

·

CVE-2014-3677

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions shim versions 0.7 shim-debuginfo versions 0.7 shim-signed versions 0.7 shim-unsigned versions 0.7 mokutil version 0.7
Description The issue affects the confidentiality, integrity, and availability of protected information in Red Hat Enterprise Linux. It can be exploited remotely, potentially leading to the execution of arbitrary code via a crafted MOK list, which triggers memory corruption.
Recommendations For shim version 0.7, consider disabling the vulnerable component until a patch is available. For shim-debuginfo version 0.7, restrict access to the vulnerable module to minimize the risk of exploitation. For shim-signed version 0.7, avoid using the crafted MOK list in the affected API endpoint until the issue is resolved. For shim-unsigned version 0.7, restrict access to the vulnerable module to minimize the risk of exploitation. For mokutil version 0.7, consider disabling the vulnerable component until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2018-2088
BDU:2015-06431
BDU:2015-06533
BDU:2015-06534
BDU:2015-06535
BDU:2015-06536
CVE-2014-3677
OPENSUSE-SU-2024:10091-1
RHSA-2014:1801
RHSA-2014_1801

Affected Products

Alt Linux
Red Hat
Suse
Mokutil
Shim
Shim-Debuginfo
Shim-Signed