audk/SecurityPkg
Jian J Wang a83dbf008c SecurityPkg/DxeImageVerificationLib: Differentiate error/search result (1) (CVE-2019-14575)
REF: https://bugzilla.tianocore.org/show_bug.cgi?id=1608

To avoid false-negative issue in check hash against dbx, both error
condition (as return value) and check result (as out parameter) of
IsCertHashFoundInDatabase() are added. So the caller of this function
will know exactly if a failure is caused by a black list hit or
other error happening, and enforce a more secure operation to prevent
secure boot from being bypassed. For a white list check (db), there's
no such necessity.

Cc: Jiewen Yao <jiewen.yao@intel.com>
Cc: Chao Zhang <chao.b.zhang@intel.com>
Signed-off-by: Jian J Wang <jian.j.wang@intel.com>
Signed-off-by: Laszlo Ersek <lersek@redhat.com>
Reviewed-by: Jiewen Yao <jiewen.yao@intel.com>
2020-02-19 14:08:23 +00:00
..
FvReportPei SecurityPkg: Fix spelling errors 2019-10-23 10:23:23 -07:00
Hash2DxeCrypto SecurityPkg/Hash2DxeCrypto: Fix few typos 2020-02-10 22:30:07 +00:00
HddPassword SecurityPkg: Fix spelling errors 2019-10-23 10:23:23 -07:00
Include SecurityPkg/Tcg: Fix various typos 2020-02-10 22:30:07 +00:00
Library SecurityPkg/DxeImageVerificationLib: Differentiate error/search result (1) (CVE-2019-14575) 2020-02-19 14:08:23 +00:00
Pkcs7Verify/Pkcs7VerifyDxe SecurityPkg: Fix few typos 2020-02-10 22:30:07 +00:00
RandomNumberGenerator/RngDxe SecurityPkg: Fix few typos 2020-02-10 22:30:07 +00:00
Tcg SecurityPkg: Issues reported by ECC in EDK2. 2020-02-14 07:27:28 +00:00
VariableAuthenticated/SecureBootConfigDxe SecurityPkg/VariableAuthenticated: Fix few typos 2020-02-10 22:30:07 +00:00
SecurityPkg.ci.yaml SecurityPkg: Add YAML files for CI builds 2019-11-11 13:02:30 -08:00
SecurityPkg.dec SecurityPkg/Guid: Add TCG 800-155 event GUID definition. 2020-01-06 06:23:19 +00:00
SecurityPkg.dsc SecurityPkg: Add YAML files for CI builds 2019-11-11 13:02:30 -08:00
SecurityPkg.uni SecurityPkg: Fix spelling errors 2019-10-23 10:23:23 -07:00
SecurityPkgExtra.uni SecurityPkg: Replace BSD License with BSD+Patent License 2019-04-09 10:58:23 -07:00