EDK II is a modern, feature-rich, cross-platform firmware development environment for the UEFI and PI specifications.
Security Fix(es):
Null pointer dereference in Tianocore EDK2 may allow an authenticated user to potentially enable escalation of privilege via local access.(CVE-2019-14584)
Insufficient input validation in MdeModulePkg in EDKII may allow an unauthenticated user to potentially enable escalation of privilege, denial of service and/or information disclosure via physical access.(CVE-2019-11098)
{ "severity": "High" }
{ "src": [ "edk2-202002-10.oe1.src.rpm" ], "x86_64": [ "edk2-devel-202002-10.oe1.x86_64.rpm", "edk2-debuginfo-202002-10.oe1.x86_64.rpm", "edk2-debugsource-202002-10.oe1.x86_64.rpm" ], "aarch64": [ "edk2-devel-202002-10.oe1.aarch64.rpm", "edk2-debuginfo-202002-10.oe1.aarch64.rpm", "edk2-debugsource-202002-10.oe1.aarch64.rpm" ], "noarch": [ "edk2-ovmf-202002-10.oe1.noarch.rpm", "python3-edk2-devel-202002-10.oe1.noarch.rpm", "edk2-aarch64-202002-10.oe1.noarch.rpm", "edk2-help-202002-10.oe1.noarch.rpm" ] }