CVE-2014-3677

shim 0.3-0.8 - Remote Code Execution via Crafted MOK List

Title source: llm
STIX 2.1

Description

Unspecified vulnerability in Shim might allow attackers to execute arbitrary code via a crafted MOK list, which triggers memory corruption.

References (4)

Core 4
Core References
Mailing List, Patch, Third Party Advisory mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2014/10/13/4
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/96989
Broken Link vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2014-1801.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/70410

Scores

EPSS 0.0274
EPSS Percentile 84.6%

Details

Status published
Products (1)
redhat/shim 0.3 - 0.8
Published Oct 22, 2014
Tracked Since Feb 18, 2026