First published: Tue Feb 26 2019(Updated: )
Buffer overflow in system firmware for EDK II may allow unauthenticated user to potentially enable escalation of privilege and/or denial of service via network access.
Credit: secure@intel.com secure@intel.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/ovmf | <0:20180508-6.gitee3198e672e2.el7 | 0:20180508-6.gitee3198e672e2.el7 |
redhat/edk2 | <0:20190308git89910a39dcfd-6.el8 | 0:20190308git89910a39dcfd-6.el8 |
Tianocore EDK II | ||
openSUSE Leap | =15.0 | |
Fedoraproject Fedora | =30 | |
Redhat Enterprise Linux | =8.0 | |
Redhat Enterprise Linux Eus | =8.1 | |
Redhat Enterprise Linux Eus | =8.2 | |
Redhat Enterprise Linux Eus | =8.4 | |
Redhat Enterprise Linux Server | =7.0 | |
Redhat Enterprise Linux Server Aus | =8.2 | |
Redhat Enterprise Linux Server Aus | =8.4 | |
Redhat Enterprise Linux Server Tus | =8.2 | |
Redhat Enterprise Linux Server Tus | =8.4 | |
debian/edk2 | 2020.11-2+deb11u2 2022.11-6+deb12u1 2024.05-2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-0160 is a vulnerability that allows an unauthenticated user to potentially enable buffer overflow in system firmware for EDK II.
The severity of CVE-2019-0160 is critical with a CVSS score of 9.8.
The software packages affected by CVE-2019-0160 include ovmf, edk2, Tianocore Edk Ii, openSUSE Leap, Fedoraproject Fedora, Redhat Enterprise Linux, Redhat Enterprise Linux Eus, Redhat Enterprise Linux Server, Redhat Enterprise Linux Server Aus, and Redhat Enterprise Linux Server Tus.
CVE-2019-0160 can be exploited by triggering buffer overflows in UDF-related codes with long file names or invalid formatted UDF media.
More information about CVE-2019-0160 can be found in the references provided: https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=1683404, https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=1683410, https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=1683413.