CVE-2014-3677
published 2014-10-22CVE-2014-3677: Unspecified vulnerability in Shim might allow attackers to execute arbitrary code via a crafted MOK list, which triggers memory corruption.
PriorityP341high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
2.74%
84.5th percentile
Unspecified vulnerability in Shim might allow attackers to execute arbitrary code via a crafted MOK list, which triggers memory corruption.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | shim | >= 0 < 0.8-0ubuntu2 | 0.8-0ubuntu2 |
| redhat | shim | >= 0.3 < 0.8 | 0.8 |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
shim: memory corruption flaw when processing Machine Owner Keys (MOKs)
vendor_redhat·2014-10-13·CVSS 7.5
CVE-2014-3677 [HIGH] CWE-787 shim: memory corruption flaw when processing Machine Owner Keys (MOKs)
shim: memory corruption flaw when processing Machine Owner Keys (MOKs)
Unspecified vulnerability in Shim might allow attackers to execute arbitrary code via a crafted MOK list, which triggers memory corruption.
An out-of-bounds memory write flaw was found in the way shim processed certain Machine Owner Keys (MOKs). A local attacker could potentially use this flaw to execute arbitrary code on the system.
GHSA
GHSA-mcwp-922h-789p: Unspecified vulnerability in Shim might allow attackers to execute arbitrary code via a crafted MOK list, which triggers memory corruption
ghsa_unreviewed·2022-05-13
CVE-2014-3677 [HIGH] GHSA-mcwp-922h-789p: Unspecified vulnerability in Shim might allow attackers to execute arbitrary code via a crafted MOK list, which triggers memory corruption
Unspecified vulnerability in Shim might allow attackers to execute arbitrary code via a crafted MOK list, which triggers memory corruption.
OSV
CVE-2014-3677: Unspecified vulnerability in Shim might allow attackers to execute arbitrary code via a crafted MOK list, which triggers memory corruption
osv·2014-10-22·CVSS 7.5
CVE-2014-3677 [HIGH] CVE-2014-3677: Unspecified vulnerability in Shim might allow attackers to execute arbitrary code via a crafted MOK list, which triggers memory corruption
Unspecified vulnerability in Shim might allow attackers to execute arbitrary code via a crafted MOK list, which triggers memory corruption.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-3676 CVE-2014-3677 CVE-2014-3675 shim: various flaws [fedora-all]
bugzilla·2014-10-14·CVSS 5.0
CVE-2014-3676 [MEDIUM] CVE-2014-3676 CVE-2014-3677 CVE-2014-3675 shim: various flaws [fedora-all]
CVE-2014-3676 CVE-2014-3677 CVE-2014-3675 shim: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fed
Bugzilla
CVE-2014-3677 shim: memory corruption flaw when processing Machine Owner Keys (MOKs)
bugzilla·2014-10-01·CVSS 7.5
CVE-2014-3677 [HIGH] CVE-2014-3677 shim: memory corruption flaw when processing Machine Owner Keys (MOKs)
CVE-2014-3677 shim: memory corruption flaw when processing Machine Owner Keys (MOKs)
A flaw was found in the way shim processed Machine Owner Keys (MOKs). This could lead to memory corruption in shim, possibly leading to arbitrary code execution.
Acknowledgements:
Red Hat would like to thank the SUSE Security Team for reporting this issue.
Discussion:
Created attachment 942903
proposed patch
---
Public now:
http://seclists.org/oss-sec/2014/q4/311
---
Created shim tracking bugs for this issue:
Affects: fedora-all [bug 1152388]
---
shim-0.8-1.fc22, shim-signed-0.8-1.fc22, mokutil-0.2.0-1.fc21 has been pushed to the Fedora 21 stable repository. If problems still persist, please make note of it in this bug report.
---
IssueDescription:
An out-of-bounds memory write flaw was fou
http://rhn.redhat.com/errata/RHSA-2014-1801.htmlhttp://www.openwall.com/lists/oss-security/2014/10/13/4http://www.securityfocus.com/bid/70410https://exchange.xforce.ibmcloud.com/vulnerabilities/96989http://rhn.redhat.com/errata/RHSA-2014-1801.htmlhttp://www.openwall.com/lists/oss-security/2014/10/13/4http://www.securityfocus.com/bid/70410https://exchange.xforce.ibmcloud.com/vulnerabilities/96989
2014-10-22
Published