Lucene search

K
osvGoogleOSV:USN-4923-1
HistoryApr 20, 2021 - 5:08 p.m.

edk2 vulnerabilities

2021-04-2017:08:41
Google
osv.dev
14
edk ii
recursion
image decompression
denial of service
arbitrary code execution
cve-2021-28210
cve-2021-28211

AI Score

7.4

Confidence

High

EPSS

0.001

Percentile

17.8%

Laszlo Ersek discovered that EDK II incorrectly handled recursion. A
remote attacker could possibly use this issue to cause EDK II to consume
resources, leading to a denial of service. (CVE-2021-28210)

Satoshi Tanda discovered that EDK II incorrectly handled decompressing
certain images. A remote attacker could use this issue to cause EDK II to
crash, resulting in a denial of service, or possibly execute arbitrary
code. (CVE-2021-28211)