File _patchinfo of Package patchinfo.14106

<patchinfo incident="14106">
  <issue tracker="bnc" id="1153072">VUL-0: CVE-2019-14553: ovmf: edk2: invalid server certificate accepted in HTTPS-over-IPv6 boot</issue>
  <issue tracker="bnc" id="1163927">VUL-0: CVE-2019-14559: ovmf: memory leak in ArpOnFrameRcvdDpc by sending invalid ARP packets</issue>
  <issue tracker="bnc" id="1163959">VUL-1: CVE-2019-14563: ovmf: numeric truncation in MdeModulePkg/PiDxeS3BootScriptLib may lead to memory corruption</issue>
  <issue tracker="bnc" id="1163969">VUL-0: CVE-2019-14575: ovmf: DxeImageVerificationHandler() fails open in case of dbx signature check</issue>
  <issue tracker="cve" id="2019-14553"/>
  <issue tracker="cve" id="2019-14559"/>
  <issue tracker="cve" id="2019-14563"/>
  <issue tracker="cve" id="2019-14575"/>
  <packager>gary_lin</packager>
  <rating>moderate</rating>
  <category>security</category>
  <summary>Security update for ovmf</summary>
  <description>This update for ovmf fixes the following issues:

Security issues fixed:

- CVE-2019-14563: Fixed a memory corruption caused by insufficient numeric truncation (bsc#1163959).
- CVE-2019-14553: Fixed the TLS certification verification in HTTPS-over-IPv6 boot sequences (bsc#1153072).
- CVE-2019-14559: Fixed a remotely exploitable memory leak in the ARP handling code (bsc#1163927).
- CVE-2019-14575: Fixed an insufficient signature check in the DxeImageVerificationHandler (bsc#1163969).
- Enabled HTTPS-over-IPv6 (bsc#1153072).
</description>
</patchinfo>
openSUSE Build Service is sponsored by