Bug ID 1128503
Summary VUL-0: CVE-2018-12181: edk2: Stack buffer overflow with corrupted BMP
Classification openSUSE
Product openSUSE Distribution
Version Leap 15.1
Hardware Other
URL https://smash.suse.de/issue/225914/
OS Other
Status NEW
Severity Normal
Priority P5 - None
Component Security
Assignee guillaume.gardet@opensuse.org
Reporter rfrohl@suse.com
QA Contact security-team@suse.de
Found By Security Response Team
Blocker ---

rh#1686783


A stack buffer overflow was found in edk2 when the HII database contains a
Bitmap who claims as 4-bit or 8-bit per pixel, but the palette contains more
than 16(2^4) or 256(2^8) colors.

Upstream issue:

https://bugzilla.tianocore.org/show_bug.cgi?id=1135


References:
https://lists.01.org/pipermail/edk2-devel/2019-March/037626.html
https://bugzilla.redhat.com/show_bug.cgi?id=1686783
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-12181


You are receiving this mail because: