CVE-2018-12183
published 2019-03-27CVE-2018-12183: Stack overflow in DxeCore for EDK II may allow an unauthenticated user to potentially enable escalation of privilege, information disclosure and/or denial of…
PriorityP425medium6.8CVSS 3.0
AVPACLPRNUINSUCHIHAH
EPSS
0.50%
39.6th percentile
Stack overflow in DxeCore for EDK II may allow an unauthenticated user to potentially enable escalation of privilege, information disclosure and/or denial of service via local access.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | edk2 | < edk2 0~20181115.85588389-1 (bookworm) | edk2 0~20181115.85588389-1 (bookworm) |
| extensible_firmware_interface_development_kit | extensible_firmware_interface_development_kit | — | — |
| tianocore | edk2 | >= 0 < 0~20181115.85588389-1 | 0~20181115.85588389-1 |
| tianocore | edk2 | >= 0 < 0~20181115.85588389-1 | 0~20181115.85588389-1 |
| tianocore | edk2 | >= 0 < 0~20181115.85588389-1 | 0~20181115.85588389-1 |
| tianocore | edk2 | >= 0 < 0~20181115.85588389-1 | 0~20181115.85588389-1 |
| tianocore | edk2 | >= 0 < 0~20160408.ffea0a2c-2ubuntu0.2+esm1 | 0~20160408.ffea0a2c-2ubuntu0.2+esm1 |
| tianocore | edk2 | >= 0 < 0~20180205.c0d9813c-2ubuntu0.3+esm1 | 0~20180205.c0d9813c-2ubuntu0.3+esm1 |
CVSS provenance
nvdv3.06.8MEDIUMCVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian6.8MEDIUM
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
EDK II vulnerabilities
vendor_ubuntu·2024-07-29·CVSS 7.8
CVE-2018-3613 [HIGH] EDK II vulnerabilities
Title: EDK II vulnerabilities
Summary: Several security issues were fixed in EDK II.
It was discovered that EDK II was not properly performing bounds checks
in Tianocompress, which could lead to a buffer overflow. An authenticated
user could use this issue to potentially escalate their privileges via
local access. (CVE-2017-5731)
It was discovered that EDK II had an insufficient memory write check in
the SMM service, which could lead to a page fault occurring. An
authenticated user could use this issue to potentially escalate their
privileges, disclose information and/or create a denial of service via
local access. (CVE-2018-12182)
It was discovered that EDK II incorrectly handled memory in DxeCore, which
could lead to a stack overflow. An unauthenticated user could this
issue to poten
Red Hat
edk2: stack overflow in DxeCore leads to privilege escalation
vendor_redhat·2019-03-29·CVSS 6.8
CVE-2018-12183 [MEDIUM] CWE-121 edk2: stack overflow in DxeCore leads to privilege escalation
edk2: stack overflow in DxeCore leads to privilege escalation
Stack overflow in DxeCore for EDK II may allow an unauthenticated user to potentially enable escalation of privilege, information disclosure and/or denial of service via local access.
Package: ovmf (Red Hat Enterprise Linux 7) - Not affected
Package: edk2 (Red Hat Enterprise Linux 8) - Not affected
Package: redhat-virtualization-host (Red Hat Virtualization 4) - Not affected
Debian
CVE-2018-12183: edk2 - Stack overflow in DxeCore for EDK II may allow an unauthenticated user to potent...
vendor_debian·2018·CVSS 6.8
CVE-2018-12183 [MEDIUM] CVE-2018-12183: edk2 - Stack overflow in DxeCore for EDK II may allow an unauthenticated user to potent...
Stack overflow in DxeCore for EDK II may allow an unauthenticated user to potentially enable escalation of privilege, information disclosure and/or denial of service via local access.
Scope: local
bookworm: resolved (fixed in 0~20181115.85588389-1)
bullseye: resolved (fixed in 0~20181115.85588389-1)
forky: resolved (fixed in 0~20181115.85588389-1)
sid: resolved (fixed in 0~20181115.85588389-1)
trixie: resolved (fixed in 0~20181115.85588389-1)
OSV
edk2 vulnerabilities
osv·2024-07-29·CVSS 7.8
CVE-2017-5731 [HIGH] edk2 vulnerabilities
edk2 vulnerabilities
It was discovered that EDK II was not properly performing bounds checks
in Tianocompress, which could lead to a buffer overflow. An authenticated
user could use this issue to potentially escalate their privileges via
local access. (CVE-2017-5731)
It was discovered that EDK II had an insufficient memory write check in
the SMM service, which could lead to a page fault occurring. An
authenticated user could use this issue to potentially escalate their
privileges, disclose information and/or create a denial of service via
local access. (CVE-2018-12182)
It was discovered that EDK II incorrectly handled memory in DxeCore, which
could lead to a stack overflow. An unauthenticated user could this
issue to potentially escalate their privileges, disclose information
and/or cre
GHSA
GHSA-9pwx-jwwh-vx6f: Stack overflow in DxeCore for EDK II may allow an unauthenticated user to potentially enable escalation of privilege, information disclosure and/or de
ghsa_unreviewed·2022-05-13
CVE-2018-12183 [MEDIUM] CWE-787 GHSA-9pwx-jwwh-vx6f: Stack overflow in DxeCore for EDK II may allow an unauthenticated user to potentially enable escalation of privilege, information disclosure and/or de
Stack overflow in DxeCore for EDK II may allow an unauthenticated user to potentially enable escalation of privilege, information disclosure and/or denial of service via local access.
OSV
CVE-2018-12183: Stack overflow in DxeCore for EDK II may allow an unauthenticated user to potentially enable escalation of privilege, information disclosure and/or de
osv·2019-03-27·CVSS 6.8
CVE-2018-12183 [MEDIUM] CVE-2018-12183: Stack overflow in DxeCore for EDK II may allow an unauthenticated user to potentially enable escalation of privilege, information disclosure and/or de
Stack overflow in DxeCore for EDK II may allow an unauthenticated user to potentially enable escalation of privilege, information disclosure and/or denial of service via local access.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-12183 edk2: stack overflow in DxeCore leads to privilege escalation
bugzilla·2019-03-29·CVSS 6.8
CVE-2018-12183 [MEDIUM] CVE-2018-12183 edk2: stack overflow in DxeCore leads to privilege escalation
CVE-2018-12183 edk2: stack overflow in DxeCore leads to privilege escalation
Stack overflow in DxeCore for EDK II may allow an unauthenticated user to potentially enable escalation of privilege, information disclosure and/or denial of service via local access.
Reference:
https://edk2-docs.gitbooks.io/security-advisory/content/unlimited-fv-recursion.html
Upstream commit:
https://github.com/tianocore/edk2/commit/0a0d5296e448fc350de1594c49b9c0deff7fad60
Discussion:
External References:
https://edk2-docs.gitbooks.io/security-advisory/content/unlimited-fv-recursion.html
---
Created edk2 tracking bugs for this issue:
Affects: fedora-all [bug 1694085]
---
Created edk2 tracking bugs for this issue:
Affects: epel-all [bug 1694086]
---
(In reply to Dhananjay Arunesh from comment #1)
>
Bugzilla
CVE-2018-12179 CVE-2018-12182 CVE-2018-12183 CVE-2019-0161 edk2: various flaws [fedora-all]
bugzilla·2019-03-29·CVSS 7.8
CVE-2018-12179 [HIGH] CVE-2018-12179 CVE-2018-12182 CVE-2018-12183 CVE-2019-0161 edk2: various flaws [fedora-all]
CVE-2018-12179 CVE-2018-12182 CVE-2018-12183 CVE-2019-0161 edk2: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supp
Bugzilla
CVE-2018-12179 CVE-2018-12182 CVE-2018-12183 CVE-2019-0161 edk2: various flaws [epel-all]
bugzilla·2019-03-29·CVSS 7.8
CVE-2018-12179 [HIGH] CVE-2018-12179 CVE-2018-12182 CVE-2018-12183 CVE-2019-0161 edk2: various flaws [epel-all]
CVE-2018-12179 CVE-2018-12182 CVE-2018-12183 CVE-2019-0161 edk2: various flaws [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supporte
http://www.securityfocus.com/bid/107643https://edk2-docs.gitbooks.io/security-advisory/content/unlimited-fv-recursion.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TQYVZRFEXSN3KS43AVH4D7QX553EZQYP/https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03912en_ushttp://www.securityfocus.com/bid/107643https://edk2-docs.gitbooks.io/security-advisory/content/unlimited-fv-recursion.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TQYVZRFEXSN3KS43AVH4D7QX553EZQYP/https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03912en_us
2019-03-27
Published