Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2020-29361

Опубликовано: 16 дек. 2020
Источник: debian

Описание

An issue was discovered in p11-kit 0.21.1 through 0.23.21. Multiple integer overflows have been discovered in the array allocations in the p11-kit library and the p11-kit list command, where overflow checks are missing before calling realloc or calloc.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
p11-kitfixed0.23.22-1package

Примечания

  • https://lists.freedesktop.org/archives/p11-glue/2020-December/000712.html

  • https://github.com/p11-glue/p11-kit/security/advisories/GHSA-q4r3-hm6m-mvc2

  • https://github.com/p11-glue/p11-kit/commit/5307a1d21a50cacd06f471a873a018d23ba4b963 (0.23.22)

  • https://github.com/p11-glue/p11-kit/commit/bd670b1d4984b27d6a397b9ddafaf89ab26e4e7f (0.23.22)

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 4 лет назад

An issue was discovered in p11-kit 0.21.1 through 0.23.21. Multiple integer overflows have been discovered in the array allocations in the p11-kit library and the p11-kit list command, where overflow checks are missing before calling realloc or calloc.

CVSS3: 7.5
redhat
больше 4 лет назад

An issue was discovered in p11-kit 0.21.1 through 0.23.21. Multiple integer overflows have been discovered in the array allocations in the p11-kit library and the p11-kit list command, where overflow checks are missing before calling realloc or calloc.

CVSS3: 7.5
nvd
больше 4 лет назад

An issue was discovered in p11-kit 0.21.1 through 0.23.21. Multiple integer overflows have been discovered in the array allocations in the p11-kit library and the p11-kit list command, where overflow checks are missing before calling realloc or calloc.

CVSS3: 7.5
msrc
больше 4 лет назад

Описание отсутствует

suse-cvrf
больше 3 лет назад

Security update for p11-kit