VulnerabilityModified
CVE-2018-12181
Stack overflow in corrupted bmp for EDK II may allow unprivileged user to potentially enable denial of service or elevation of privilege via local access.
MEDIUM 6.0EPSS 0.43%
Does this matter?
Lower severity and a low EPSS score (0.43%). Track it; it rarely justifies an emergency change on its own.
Description
Stack overflow in corrupted bmp for EDK II may allow unprivileged user to potentially enable denial of service or elevation of privilege via local access.
- CVSS 3.0
- 6.0 MEDIUMCVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
- EPSS
- 0.43% probability · 36th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-787
- Affected
- tianocore/edk ii
- Source
- secure@intel.com
References
- http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00030.html
- http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00048.html
- https://access.redhat.com/errata/RHSA-2019:2125
- https://access.redhat.com/errata/RHSA-2019:3338
- https://edk2-docs.gitbooks.io/security-advisory/content/stack-overflow-on-corrupted-bmp.htmlPatch, Vendor Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4ABTDKZK2G5XP6JCO3HXMPOA2NRTIYDZ/
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03912en_us
- https://usn.ubuntu.com/4349-1/
- http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00030.html
- http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00048.html
- https://access.redhat.com/errata/RHSA-2019:2125
- https://access.redhat.com/errata/RHSA-2019:3338
- https://edk2-docs.gitbooks.io/security-advisory/content/stack-overflow-on-corrupted-bmp.htmlPatch, Vendor Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4ABTDKZK2G5XP6JCO3HXMPOA2NRTIYDZ/
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03912en_us
- https://usn.ubuntu.com/4349-1/
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.