CVE-2018-12178: Buffer Overflow
Published Mar 27, 2019
·Updated
Buffer overflow in network stack for EDK II may allow unprivileged user to potentially enable escalation of privilege and/or denial of service via network.
Affected Software
2 affected componentsFixes available
Tianocore EDK II
debian/edk2
2020.11-2+deb11u22020.11-2+deb11u32022.11-6+deb12u22022.11-6+deb12u12025.02-8+deb13u12025.02-92025.11-4
Remediation
Event History
Mar 27, 2019
CVE Published
via MITRE·07:19 PM
Data Sourced
via MITRE·07:19 PM
DescriptionWeakness
Data Sourced
via NVD·08:29 PM
RemedyDescriptionSeverityWeaknessAffected Software
Feb 20, 2026
Data Sourced
via Ubuntu·04:24 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Debian·04:25 PM
DescriptionAffected Software
Data Sourced
via Launchpad·04:25 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-12178?
The severity of CVE-2018-12178 is critical with a CVSS score of 9.1.
2
How can an unprivileged user potentially exploit CVE-2018-12178?
An unprivileged user can potentially exploit CVE-2018-12178 to enable escalation of privilege and/or denial of service via the network.
3
What is the affected software for CVE-2018-12178?
The affected software for CVE-2018-12178 is EDK II on Debian and Ubuntu.
4
How can I fix CVE-2018-12178 on Debian?
To fix CVE-2018-12178 on Debian, update the edk2 package to version 0~20181115.85588389-3+deb10u3 or later.
5
How can I fix CVE-2018-12178 on Ubuntu?
To fix CVE-2018-12178 on Ubuntu, update the edk2 package to the appropriate version based on the affected release (e.g., bionic, xenial).