Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2020-10759

Опубликовано: 15 сент. 2020
Источник: debian
EPSS Низкий

Описание

A PGP signature bypass flaw was found in fwupd (all versions), which could lead to the installation of unsigned firmware. As per upstream, a signature bypass is theoretically possible, but not practical because the Linux Vendor Firmware Service (LVFS) is either not implemented or enabled in versions of fwupd shipped with Red Hat Enterprise Linux 7 and 8. The highest threat from this vulnerability is to confidentiality and integrity.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
fwupdfixed1.3.10-1package
fwupdfixed1.2.13-1busterpackage
libjcatfixed0.1.3-1package

Примечания

  • https://bugzilla.redhat.com/show_bug.cgi?id=1844316

  • https://github.com/justinsteven/advisories/blob/master/2020_fwupd_dangling_s3_bucket_and_CVE-2020-10759_signature_verification_bypass.md

  • Fixed by: https://github.com/fwupd/fwupd/commit/21f2d12fccef63b8aaa99ec53278ce18250b0444 (1.3.10)

  • Introduced with: https://github.com/fwupd/fwupd/commit/36a889034c3d34ae4ac4530ea7b6b16e82476fae (0.1.2)

  • https://github.com/hughsie/libjcat/commit/839b89f45a38b2373bf5836337a33f450aaab72e

EPSS

Процентиль: 4%
0.00021
Низкий

Связанные уязвимости

CVSS3: 6
ubuntu
почти 5 лет назад

A PGP signature bypass flaw was found in fwupd (all versions), which could lead to the installation of unsigned firmware. As per upstream, a signature bypass is theoretically possible, but not practical because the Linux Vendor Firmware Service (LVFS) is either not implemented or enabled in versions of fwupd shipped with Red Hat Enterprise Linux 7 and 8. The highest threat from this vulnerability is to confidentiality and integrity.

CVSS3: 5.7
redhat
около 5 лет назад

A PGP signature bypass flaw was found in fwupd (all versions), which could lead to the installation of unsigned firmware. As per upstream, a signature bypass is theoretically possible, but not practical because the Linux Vendor Firmware Service (LVFS) is either not implemented or enabled in versions of fwupd shipped with Red Hat Enterprise Linux 7 and 8. The highest threat from this vulnerability is to confidentiality and integrity.

CVSS3: 6
nvd
почти 5 лет назад

A PGP signature bypass flaw was found in fwupd (all versions), which could lead to the installation of unsigned firmware. As per upstream, a signature bypass is theoretically possible, but not practical because the Linux Vendor Firmware Service (LVFS) is either not implemented or enabled in versions of fwupd shipped with Red Hat Enterprise Linux 7 and 8. The highest threat from this vulnerability is to confidentiality and integrity.

suse-cvrf
около 4 лет назад

Security update for fwupd

suse-cvrf
почти 5 лет назад

Security update for fwupd

EPSS

Процентиль: 4%
0.00021
Низкий