CVE-2018-12178
Public on 2019-03-27
Modified on 2019-08-27
Description
A missing check leads to an out-of-bounds read and write flaw in NetworkPkg/DnsDxe as shipped in edk2, when it parses DNS responses. A remote attacker who controls the DNS server used by the vulnerable firmware may use this flaw to make the system crash.
Severity
CVSS v3 Base Score
See breakdown
Affected Packages
Platform | Package | Release Date | Advisory | Status |
---|---|---|---|---|
Amazon Linux 2 - Core | edk2 | 2019-08-23 | ALAS2-2019-1273 | Fixed |
CVSS Scores
Score Type | Score | Vector | |
---|---|---|---|
Amazon Linux | CVSSv3 | 7.2 | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:L |
NVD | CVSSv2 | 6.4 | AV:N/AC:L/Au:N/C:N/I:P/A:P |
NVD | CVSSv3 | 9.1 | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H |