First published: Thu Feb 06 2020(Updated: )
Buffer overflow in the Reclaim function in Tianocore EDK2 before SVN 16280 allows physically proximate attackers to gain privileges via a long variable name.
Credit: cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
Tianocore EDK II | <svn_16280 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-8271 is a vulnerability that allows physically proximate attackers to gain privileges via a buffer overflow in the Reclaim function in Tianocore EDK2 before SVN 16280.
CVE-2014-8271 has a severity rating of 6.8 out of 10 (medium severity).
Tianocore EDK2 versions before SVN 16280 are affected by CVE-2014-8271.
Physically proximate attackers can exploit CVE-2014-8271 by using a long variable name to trigger a buffer overflow in the Reclaim function of Tianocore EDK2.
Yes, an updated version of Tianocore EDK2 (SVN 16280 or newer) addresses the vulnerability. It is recommended to upgrade to the latest version to mitigate the risk.