QID 379359
Date Published: 2024-02-09
QID 379359: Shim package Multiple Vulnerabilities
Shim is an open-source projects and other third parties built a small application, that contains the vendor certificate and code that verifies and runs the bootloader (typically GRUB2).
Shilm is affected with multiple security vulnerabilities.
CVE-2023-40547 Remote code execution vulnerability was found in Shim
CVE-2023-40546 Fixes a LogError() invocation (NULL pointer dereference)
CVE-2023-40548 Fixes an integer overflow on SBAT section size on 32-bit systems (heap overflow)
CVE-2023-40549 Fixes an out-of-bounds read when loading a PE binary
CVE-2023-40550 Fixes an out-of-bounds read when trying to validate the SBAT information
CVE-2023-40551 Fix bounds check for MZ binaries
Successful exploitation of this vulnerability could lead to a security breach or could lead to remote code execution, crash, denial of service and exposure of sensitive data
CVEs related to QID 379359
| Advisory ID | Software | Component | Link |
|---|