Results 1 to 3 of 3

Thread: any fix for CVE-2023-40547 on ubuntu?

  1. #1
    Join Date
    Oct 2021
    Beans
    38

    any fix for CVE-2023-40547 on ubuntu?

    noted https://ubuntu.com/security/CVE-2023-40547 and elsewhere.
    anything?

  2. #2
    Join Date
    Mar 2010
    Location
    Squidbilly-Land
    Beans
    Hidden!
    Distro
    Ubuntu

    Re: any fix for CVE-2023-40547 on ubuntu?

    Do you use an OS boot server with http? If you don't, like home users wouldn't, seems to be a non-issue.

    Or did I misread the CVE?

    A remote code execution vulnerability was found in Shim. The Shim boot support trusts attacker-controlled values when parsing an HTTP response. This flaw allows an attacker to craft a specific malicious HTTP request, leading to a completely controlled out-of-bounds write primitive and complete system compromise. This flaw is only exploitable during the early boot phase, an attacker needs to perform a Man-in-the-Middle or compromise the boot server to be able to exploit this vulnerability successfully.
    None of my systems for any OS are vulnerable.

  3. #3
    Join Date
    Oct 2021
    Beans
    38

    Re: any fix for CVE-2023-40547 on ubuntu?

    Thanks, looks like I misread the CVE.

Tags for this Thread

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •