http://bugzilla.opensuse.org/show_bug.cgi?id=1128503 Bug ID: 1128503 Summary: VUL-0: CVE-2018-12181: edk2: Stack buffer overflow with corrupted BMP Classification: openSUSE Product: openSUSE Distribution Version: Leap 15.1 Hardware: Other URL: https://smash.suse.de/issue/225914/ OS: Other Status: NEW Severity: Normal Priority: P5 - None Component: Security Assignee: guillaume.gardet@opensuse.org Reporter: rfrohl@suse.com QA Contact: security-team@suse.de Found By: Security Response Team Blocker: --- rh#1686783 A stack buffer overflow was found in edk2 when the HII database contains a Bitmap who claims as 4-bit or 8-bit per pixel, but the palette contains more than 16(2^4) or 256(2^8) colors. Upstream issue: https://bugzilla.tianocore.org/show_bug.cgi?id=1135 References: https://lists.01.org/pipermail/edk2-devel/2019-March/037626.html https://bugzilla.redhat.com/show_bug.cgi?id=1686783 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-12181 -- You are receiving this mail because: You are on the CC list for the bug.