Your message dated Mon, 26 Jul 2021 07:32:58 -0600
with message-id <[email protected]>
and subject line closing
has caused the Debian Bug report #991495,
regarding edk2: CVE-2019-11098
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
991495: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=991495
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: edk2
X-Debbugs-CC: [email protected]
Severity: important
Tags: security

Hi,

The following vulnerability was published for edk2.

CVE-2019-11098[0]:
| Insufficient input validation in MdeModulePkg in EDKII may allow an
| unauthenticated user to potentially enable escalation of privilege,
| denial of service and/or information disclosure via physical access.

https://edk2-docs.gitbook.io/security-advisory/bootguard-toctou-vulnerability
https://bugzilla.tianocore.org/show_bug.cgi?id=1614
https://bugzilla.tianocore.org/attachment.cgi?id=316


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2019-11098
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-11098

Please adjust the affected versions in the BTS as needed.

--- End Message ---
--- Begin Message ---
Version: 2021.02-1

--- End Message ---

Reply via email to