Lucene search

K
osvGoogleOSV:USN-4684-1
HistoryJan 07, 2021 - 1:51 p.m.

edk2 vulnerabilities

2021-01-0713:51:25
Google
osv.dev
4

7.8 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

12.6%

Laszlo Ersek discovered that EDK II incorrectly validated certain signed
images. An attacker could possibly use this issue with a specially crafted
image to cause EDK II to hang, resulting in a denial of service. This issue
only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, and Ubuntu 20.04 LTS.
(CVE-2019-14562)

It was discovered that EDK II incorrectly parsed signed PKCS #7 data. An
attacker could use this issue to cause EDK II to crash, resulting in a
denial of service, or possibly execute arbitrary code. (CVE-2019-14584)