mirror of
https://github.com/0xMarcio/cve.git
synced 2025-05-06 02:31:38 +00:00
1000 B
1000 B
CVE-2023-45233
Description
EDK2's Network Package is susceptible to an infinite lop vulnerability when parsing a PadN option in the Destination Options header of IPv6. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Availability.
POC
Reference
- http://packetstormsecurity.com/files/176574/PixieFail-Proof-Of-Concepts.html
- http://packetstormsecurity.com/files/176574/PixieFail-Proof-Of-Concepts.html