First published: Mon Sep 24 2018(Updated: )
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none.
Credit: Intel Eclypsium Intel Eclypsium Intel Eclypsium Intel Eclypsium Intel Eclypsium cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/ovmf | <0:20180508-6.gitee3198e672e2.el7 | 0:20180508-6.gitee3198e672e2.el7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2017-5734 is a firmware vulnerability that involves a memory corruption issue that has been addressed with improved input validation.
The affected software includes the ovmf package with version 0:20180508-6.gitee3198e672e2.el7 from Red Hat, and macOS Mojave version up to and excluding 10.14 from Apple.
The severity of CVE-2017-5734 is medium, with a severity value of 6.7.
To fix CVE-2017-5734, ensure that you have installed the updated ovmf package with version 0:20180508-6.gitee3198e672e2.el7 from Red Hat, or update your macOS Mojave to a version higher than 10.14.
You can find more information about CVE-2017-5734 at the following references: [Link 1](https://edk2-docs.gitbooks.io/security-advisory/content/edk-ii-tianocompress-bounds-checking-issues.html), [Link 2](https://bugzilla.tianocore.org/show_bug.cgi?id=686), [Link 3](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=1641462).