cbcvebase.
CVE-2019-14562
published 2020-11-23

CVE-2019-14562: Integer overflow in DxeImageVerificationHandler() EDK II may allow an authenticated user to potentially enable denial of service via local access.

medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
Integer overflow in DxeImageVerificationHandler() EDK II may allow an authenticated user to potentially enable denial of service via local access.

Affected

9 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianedk2< edk2 2020.05-4 (bookworm)edk2 2020.05-4 (bookworm)
tianocoreedk2>= 0 < 2020.05-42020.05-4
tianocoreedk2>= 0 < 2020.05-42020.05-4
tianocoreedk2>= 0 < 2020.05-42020.05-4
tianocoreedk2>= 0 < 2020.05-42020.05-4
tianocoreedk2>= 0 < 0~20160408.ffea0a2c-2ubuntu0.20~20160408.ffea0a2c-2ubuntu0.2
tianocoreedk2>= 0 < 0~20180205.c0d9813c-2ubuntu0.30~20180205.c0d9813c-2ubuntu0.3
tianocoreedk2>= 0 < 0~20191122.bd85bf54-2ubuntu3.10~20191122.bd85bf54-2ubuntu3.1

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM