Show plain JSON{"affected_release": [{"advisory": "RHSA-2019:2125", "cpe": "cpe:/o:redhat:enterprise_linux:7", "package": "ovmf-0:20180508-6.gitee3198e672e2.el7", "product_name": "Red Hat Enterprise Linux 7", "release_date": "2019-08-06T00:00:00Z"}], "bugzilla": {"description": "edk2: Privilege escalation via processing of malformed files in BaseUefiDecompressLib.c", "id": "1641446", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1641446"}, "csaw": false, "cvss3": {"cvss3_base_score": "6.7", "cvss3_scoring_vector": "CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H", "status": "verified"}, "cwe": "CWE-287", "details": ["[REJECTED CVE] A vulnerability exists in EDK-2 within BaseUefiDecompressLib.c (MdePkg/Library/BaseUefiDecompressLib). An authenticated attacker could exploit this vulnerability by supplying a crafted file, potentially leading to privilege escalation."], "name": "CVE-2017-5732", "package_state": [{"cpe": "cpe:/o:redhat:enterprise_linux:8", "fix_state": "Not affected", "package_name": "edk2", "product_name": "Red Hat Enterprise Linux 8"}], "public_date": "2018-10-16T00:00:00Z", "references": ["https://www.cve.org/CVERecord?id=CVE-2017-5732\nhttps://nvd.nist.gov/vuln/detail/CVE-2017-5732\nhttps://edk2-docs.gitbooks.io/security-advisory/content/edk-ii-tianocompress-bounds-checking-issues.html"], "threat_severity": "Moderate"}