34. PartitionDxe and Udf Buffer Overflow
Description:
Buffer overflow in system firmware for EDK II may allow unauthenticated user to potentially enable escalation of privilege and/or denial of service via network access.
Impact
Escalation of privilege and/or denial of service
Severity
8.7 (High) - CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:H
Recommendation:
EDK II Commits:
- https://github.com/tianocore/edk2/commit/4df8f5bfa28b8b881e506437e8f08d92c1a00370
- https://github.com/tianocore/edk2/commit/b9ae1705adfdd43668027a25a2b03c2e81960219
- https://github.com/tianocore/edk2/commit/5c0748f43f4e1cc15fdd0be64a764eacd7df92f6
- https://github.com/tianocore/edk2/commit/89f75aa04a97293a8ed9db2a90851a5053730cf5
- https://github.com/tianocore/edk2/commit/3b30351b75d70ea65701ac999875fbb81a89a5ca
Patch:
Acknowledgments:
Intel Team
References:
CVE-2019-0160
EDK II Bugzilla #828