Alerts This Week
Warning Icon 1 700
Alerts This Week
Warning Icon 1 700

Fedora 30: FEDORA-2019-3b96bb5186 Critical: EDK2 Buffer Overflow Fix

fedora
Calendar Grey March 30, 2019
Dist Fedora Esm H88
Crucial modifications for edk2 within Fedora 30 aimed at boosting security through package enhancements and alterations in dependencies.
Use YYYYMMDD versioning to fix upgrade path ---- * Update to stable-201903 * Update to openssl-1.1.0j * Move to python3 deps

Summary

EDK II is a development code base for creating UEFI drivers, applications

and firmware images.

Use YYYYMMDD versioning to fix upgrade path ---- * Update to stable-201903 *

Update to openssl-1.1.0j * Move to python3 deps

[ 1 ] Bug #1641442 - CVE-2017-5731 edk2: Privilege escalation via processing of malformed files in TianoCompress.c

https://bugzilla.redhat.com/show_bug.cgi?id=1641442

[ 2 ] Bug #1641446 - CVE-2017-5732 edk2: Privilege escalation via processing of malformed files in BaseUefiDecompressLib.c

https://bugzilla.redhat.com/show_bug.cgi?id=1641446

[ 3 ] Bug #1641450 - CVE-2017-5733 edk2: Privilege escalation via heap-based buffer overflow in MakeTable() function

https://bugzilla.redhat.com/show_bug.cgi?id=1641450

[ 4 ] Bug #1641458 - CVE-2017-5734 edk2: Privilege escalation via stack-based buffer overflow in MakeTable() function

https://bugzilla.redhat.com/show_bug.cgi?id=1641458

[ 5 ] Bug #1641465 - CVE-2017-5735 edk2: Privilege escalation via heap-based buffer overflow in Decode() function

https://bugzilla.redhat.com/show_bug.cgi?id=1641465

[ 6 ] Bug #1683326 - CVE-2018-12178 edk2: improper DNS packet size check

https://bugzilla.redhat.com/show_bug.cgi?id=1683326

[ 7 ] Bug #1683372 - CVE-2018-12180 edk2: Buffer Overflow in BlockIo service for RAM disk

https://bugzilla.redhat.com/show_bug.cgi?id=1683372

[ 8 ] Bug #1686783 - CVE-2018-12181 edk2: Stack buffer overflow with corrupted BMP

https://bugzilla.redhat.com/show_bug.cgi?id=1686783

[ 9 ] Bug #1641433 - CVE-2018-3613 edk2: Logic error in MdeModulePkg in EDK II firmware allows for privilege escalation by authenticated users

https://bugzilla.redhat.com/show_bug.cgi?id=1641433

[ 10 ] Bug #1683653 - CVE-2018-3630 ovmf: Logic error in FV parsing in MdeModulePkg\Core\Pei\FwVol\FwVol.c

https://bugzilla.redhat.com/show_bug.cgi?id=1683653

[ 11 ] Bug #1683421 - edk2: heap buffer overflow in LengthofComponentIdentifier in UdfDxe/FileSystemOperations.c

https://bugzilla.redhat.com/show_bug.cgi?id=1683421

[ 12 ] Bug #1683425 - edk2: heap buffer overflow in NumberOfPartitions in UdfDxe/FileSystemOperations.c

https://bugzilla.redhat.com/show_bug.cgi?id=1683425

[ 13 ] Bug #1683413 - edk2: heap buffer overflow in ReadFile in UdfDxe/FileSystemOperations.c

https://bugzilla.redhat.com/show_bug.cgi?id=1683413

[ 14 ] Bug #1683404 - edk2: stack buffer overflow in file/path name string check in UdfDxe/File.c

https://bugzilla.redhat.com/show_bug.cgi?id=1683404

[ 15 ] Bug #1683410 - edk2: stack buffer overflow in FindAnchorVolumeDescriptorPointer in PartitionDxe/Udf.c

https://bugzilla.redhat.com/show_bug.cgi?id=1683410

su -c 'dnf upgrade --advisory FEDORA-2019-3b96bb5186' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/

List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Change Log

References

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Product: Fedora 30
Version: 20190308stable
Release: 1.fc30
Summary: EFI Development Kit II

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here