A remote code execution vulnerability was found in Shim....
High severity
Unreviewed
Published
Jan 25, 2024
to the GitHub Advisory Database
•
Updated Jun 10, 2024
Description
Published by the National Vulnerability Database
Jan 25, 2024
Published to the GitHub Advisory Database
Jan 25, 2024
Last updated
Jun 10, 2024
A remote code execution vulnerability was found in Shim. The Shim boot support trusts attacker-controlled values when parsing an HTTP response. This flaw allows an attacker to craft a specific malicious HTTP request, leading to a completely controlled out-of-bounds write primitive and complete system compromise.
References