Bug ID | 1128503 |
---|---|
Summary | VUL-0: CVE-2018-12181: edk2: Stack buffer overflow with corrupted BMP |
Classification | openSUSE |
Product | openSUSE Distribution |
Version | Leap 15.1 |
Hardware | Other |
URL | https://smash.suse.de/issue/225914/ |
OS | Other |
Status | NEW |
Severity | Normal |
Priority | P5 - None |
Component | Security |
Assignee | guillaume.gardet@opensuse.org |
Reporter | rfrohl@suse.com |
QA Contact | security-team@suse.de |
Found By | Security Response Team |
Blocker | --- |
rh#1686783 A stack buffer overflow was found in edk2 when the HII database contains a Bitmap who claims as 4-bit or 8-bit per pixel, but the palette contains more than 16(2^4) or 256(2^8) colors. Upstream issue: https://bugzilla.tianocore.org/show_bug.cgi?id=1135 References: https://lists.01.org/pipermail/edk2-devel/2019-March/037626.html https://bugzilla.redhat.com/show_bug.cgi?id=1686783 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-12181