Description
An out-of-bounds read flaw was found in Shim due to the lack of proper boundary verification during the load of a PE binary. This flaw allows an attacker to load a crafted PE binary, triggering the issue and crashing Shim, resulting in a denial of service.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Workaround
There's no available mitigation for this issue.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-3813-1 | shim security update |
EUVD |
EUVD-2023-45120 | An out-of-bounds read flaw was found in Shim due to the lack of proper boundary verification during the load of a PE binary. This flaw allows an attacker to load a crafted PE binary, triggering the issue and crashing Shim, resulting in a denial of service. |
References
History
Sun, 24 Nov 2024 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2025-11-20T19:53:36.835Z
Reserved: 2023-08-15T20:04:15.615Z
Link: CVE-2023-40549
Updated: 2024-08-02T18:38:50.333Z
Status : Modified
Published: 2024-01-29T17:15:08.580
Modified: 2024-11-21T08:19:42.003
Link: CVE-2023-40549
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
EUVD