SUSE-SU-2021:2117-1
Dashboard / Vulnerabilities / SUSE-SU-2021:2117-1
SUSE-SU-2021:2117-1
Summary: Security update for ovmf
Details: This update for ovmf fixes the following issues: - Fixed a possible buffer overflow in IScsiDxe (bsc#1186151) - CVE-2021-28211: ovmf: edk2: possible heap corruption with LzmaUefiDecompressGetInfo (bsc#1183578) - CVE-2021-28210: ovmf: unlimited FV recursion, round 2 (bsc#1183579) - CVE-2019-14584: ovmf,shim: NULL pointer dereference in AuthenticodeVerify() (bsc#1177789)
References: https://www.suse.com/support/update/announcement/2021/suse-su-20212117-1/, https://bugzilla.suse.com/1177789, https://bugzilla.suse.com/1183578, https://bugzilla.suse.com/1183579, https://bugzilla.suse.com/1186151, https://www.suse.com/security/cve/CVE-2019-14584, https://www.suse.com/security/cve/CVE-2021-28210, https://www.suse.com/security/cve/CVE-2021-28211
Affected packages
Package
Name: ovmf
Purl: pkg:rpm/suse/ovmf&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2-BCL
Affected ranges
Type: ECOSYSTEM
Events:
