First published: Thu Mar 07 2019(Updated: )
A stack buffer overflow was found in edk2 when the HII database contains a Bitmap who claims as 4-bit or 8-bit per pixel, but the palette contains more than 16(2^4) or 256(2^8) colors. Upstream issue: <a href="https://bugzilla.tianocore.org/show_bug.cgi?id=1135">https://bugzilla.tianocore.org/show_bug.cgi?id=1135</a> References: <a href="https://lists.01.org/pipermail/edk2-devel/2019-March/037626.html">https://lists.01.org/pipermail/edk2-devel/2019-March/037626.html</a>
Credit: secure@intel.com secure@intel.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/ovmf | <0:20180508-6.gitee3198e672e2.el7 | 0:20180508-6.gitee3198e672e2.el7 |
redhat/edk2 | <0:20190308git89910a39dcfd-6.el8 | 0:20190308git89910a39dcfd-6.el8 |
Tianocore EDK II | ||
debian/edk2 | 2020.11-2+deb11u2 2022.11-6+deb12u1 2024.05-2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-12181 is a vulnerability that allows an unprivileged user to potentially enable denial of service through a stack overflow in corrupted bmp for EDK II.
CVE-2018-12181 has a severity level of medium.
The affected software includes ovmf version 0:20180508-6.gitee3198e672e2.el7, edk2 version 0:20190308git89910a39dcfd-6.el8, and several versions of edk2 in Debian and Ubuntu.
To fix CVE-2018-12181, update the affected software to the recommended versions provided by the respective vendors.
You can find more information about CVE-2018-12181 on the following references: [link1](https://bugzilla.tianocore.org/show_bug.cgi?id=1135), [link2](https://lists.01.org/pipermail/edk2-devel/2019-March/037626.html), [link3](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=1686785).