REDHAT-BUG-1641446: Medium severity edk ii vulnerability
In EDK II, a vulnerability exists in BaseUefiDecompressLib.c (MdePkg/Library/BaseUefiDecompressLib). An authenticated attacker could exploit this via a crafted file to escalate privileges.
External Reference:
https://edk2-docs.gitbooks.io/security-advisory/content/edk-ii-tianocompress-bounds-checking-issues.html
Upstream Bug:
https://bugzilla.tianocore.org/showbug.cgi?id=686
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1641446?
The severity of REDHAT-BUG-1641446 is high due to its potential for privilege escalation by an authenticated attacker.
How do I fix REDHAT-BUG-1641446?
To fix REDHAT-BUG-1641446, ensure that you apply the latest patches and updates provided by TianoCore for EDK II.
What is affected by REDHAT-BUG-1641446?
REDHAT-BUG-1641446 affects the TianoCore EDK II software package.
Can an unauthenticated user exploit REDHAT-BUG-1641446?
No, only an authenticated attacker can exploit the vulnerability described in REDHAT-BUG-1641446.
What can an attacker gain by exploiting REDHAT-BUG-1641446?
An attacker exploiting REDHAT-BUG-1641446 could gain elevated privileges on the affected system.