USN-6638-1
Dashboard / Vulnerabilities / USN-6638-1
USN-6638-1
Summary: edk2 vulnerabilities
Details: Marc Beatove discovered buffer overflows exit in EDK2. An attacker on the local network could potentially use this to impact availability or possibly cause remote code execution. (CVE-2022-36763, CVE-2022-36764, CVE-2022-36765) It was discovered that a buffer overflows exists in EDK2's Network Package An attacker on the local network could potentially use these to impact availability or possibly cause remote code execution. (CVE-2023-45230, CVE-2023-45234, CVE-2023-45235) It was discovered that an out-of-bounds read exists in EDK2's Network Package An attacker on the local network could potentially use this to impact confidentiality. (CVE-2023-45231) It was discovered that infinite-loops exists in EDK2's Network Package An attacker on the local network could potentially use these to impact availability. (CVE-2023-45232, CVE-2023-45233) Mate Kukri discovered that an insecure default to allow UEFI Shell in EDK2 was left enabled in Ubuntu's EDK2. An attacker could use this to bypass Secure Boot. (CVE-2023-48733)
References: https://ubuntu.com/security/notices/USN-6638-1, https://ubuntu.com/security/CVE-2022-36763, https://ubuntu.com/security/CVE-2022-36764, https://ubuntu.com/security/CVE-2022-36765, https://ubuntu.com/security/CVE-2023-45230, https://ubuntu.com/security/CVE-2023-45231, https://ubuntu.com/security/CVE-2023-45232, https://ubuntu.com/security/CVE-2023-45233, https://ubuntu.com/security/CVE-2023-45234, https://ubuntu.com/security/CVE-2023-45235, https://ubuntu.com/security/CVE-2023-48733, https://bugs.launchpad.net/ubuntu/+source/edk2/+bug/2040137
Affected packages
Package
Name: edk2
Purl: pkg:deb/ubuntu/edk2@0~20191122.bd85bf54-2ubuntu3.5?arch=source&distro=focal
Affected ranges
Type: ECOSYSTEM
Events:
