USN-4923-1
Dashboard / Vulnerabilities / USN-4923-1
USN-4923-1
Summary: edk2 vulnerabilities
Details: Laszlo Ersek discovered that EDK II incorrectly handled recursion. A remote attacker could possibly use this issue to cause EDK II to consume resources, leading to a denial of service. (CVE-2021-28210) Satoshi Tanda discovered that EDK II incorrectly handled decompressing certain images. A remote attacker could use this issue to cause EDK II to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2021-28211)
References: https://ubuntu.com/security/notices/USN-4923-1, https://ubuntu.com/security/CVE-2021-28210, https://ubuntu.com/security/CVE-2021-28211
Affected packages
Package
Name: edk2
Purl: pkg:deb/ubuntu/edk2@0~20191122.bd85bf54-2ubuntu3.2?arch=source&distro=focal
Affected ranges
Type: ECOSYSTEM
Events:
