CVE-2014-3676: Buffer Overflow
Published Oct 22, 2014
·Updated
Heap-based buffer overflow in Shim allows remote attackers to execute arbitrary code via a crafted IPv6 address, related to the "tftp:// DHCPv6 boot option."
Affected Software
1 affected component
redhat Shim>=0.3<0.8
Event History
Oct 22, 2014
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-3676?
CVE-2014-3676 has a critical severity due to the potential for remote code execution.
2
How do I fix CVE-2014-3676?
To fix CVE-2014-3676, update to the latest version of Red Hat Shim that addresses this vulnerability.
3
What types of systems are affected by CVE-2014-3676?
CVE-2014-3676 affects systems running the vulnerable versions of Red Hat Shim from 0.3 up to 0.8.
4
What exploit method is used in CVE-2014-3676?
CVE-2014-3676 allows attackers to exploit the vulnerability via a crafted IPv6 address.
5
Is there a known attack vector for CVE-2014-3676?
Yes, the attack vector for CVE-2014-3676 is related to the "tftp:// DHCPv6 boot option."