PT-2018-2658 · Tianocore+3 · Edk Ii+3

Published

2018-07-02

·

Updated

2024-06-15

·

CVE-2018-12178

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions EDK II (affected versions not specified)
Description The issue is related to a buffer overflow in the network stack for EDK II, which may allow an unprivileged user to potentially enable escalation of privilege and/or denial of service via the network. The vulnerability is caused by insufficient validation of user input data in the Tianocore edk2 library. Exploitation of the vulnerability may allow a remote attacker to elevate their privileges or cause a denial of service.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Buffer Overflow

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2019-1581
BDU:2019-01290
CVE-2018-12178
OPENSUSE-SU-2019:1083-1
OPENSUSE-SU-2019_0348-1
OPENSUSE-SU-2019_1083-1
OPENSUSE-SU-2024:11134-1
SUSE-SU-2019:0579-1
SUSE-SU-2019:0580-1
SUSE-SU-2019:0581-1
SUSE-SU-2019_0579-1
SUSE-SU-2019_0580-1
SUSE-SU-2019_0581-1
USN-4349-1

Affected Products

Alt Linux
Edk Ii
Suse
Ubuntu