CVE-2023-45235: Buffer Overflow in EDK II Network Package
Buffer Overflow in EDK II Network Package
Other sources
EDK2's Network Package is susceptible to a buffer overflow vulnerability when handling Server ID option from a DHCPv6 proxy Advertise message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality, Integrity and/or Availability.
— Ubuntu
https://blog.quarkslab.com/pixiefail-nine-vulnerabilities-in-tianocores-edk-ii-ipv6-network-stack.html https://github.com/advisories/GHSA-h9v6-q439-p7j2
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-45235?
CVE-2023-45235 has a high severity due to its potential to allow unauthorized access and data loss.
How do I fix CVE-2023-45235?
To fix CVE-2023-45235, update EDK II to the latest version that addresses this vulnerability.
What type of vulnerability is CVE-2023-45235?
CVE-2023-45235 is a buffer overflow vulnerability related to DHCPv6 proxy Advertise message handling.
How can CVE-2023-45235 be exploited?
CVE-2023-45235 can be exploited by an attacker manipulating DHCPv6 messages to gain unauthorized access.
What software is affected by CVE-2023-45235?
CVE-2023-45235 affects various versions of Tianocore's EDK II on multiple platforms including Ubuntu and Debian.