CVE-2019-14562: Integer Overflow
Published Nov 23, 2020
·Updated
Integer overflow in DxeImageVerificationHandler() EDK II may allow an authenticated user to potentially enable denial of service via local access.
Affected Software
2 affected components
Tianocore edk2
Debian Debian Linux=9.0
Event History
Nov 23, 2020
CVE Published
via MITRE·03:50 PM
Data Sourced
via MITRE·03:50 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2019-14562.
2
What is the title of this vulnerability?
The title of this vulnerability is 'Integer overflow in DxeImageVerificationHandler() EDK II may allow an authenticated user to potentially enable denial of service via local access.'
3
What is the severity of CVE-2019-14562?
The severity of CVE-2019-14562 is medium with a CVSS score of 5.5.
4
Which software is affected by CVE-2019-14562?
Tianocore EDK2 and Debian Debian Linux version 9.0 are affected by CVE-2019-14562.
5
How can an authenticated user potentially exploit CVE-2019-14562?
An authenticated user may potentially enable denial of service via local access by exploiting the integer overflow in DxeImageVerificationHandler() in EDK II.