Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2022-47630

Опубликовано: 16 янв. 2023
Источник: debian
EPSS Низкий

Описание

Trusted Firmware-A through 2.8 has an out-of-bounds read in the X.509 parser for parsing boot certificates. This affects downstream use of get_ext and auth_nvctr. Attackers might be able to trigger dangerous read side effects or obtain sensitive information about microarchitectural state.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
arm-trusted-firmwarefixed2.9.0+dfsg-3package

Примечания

  • https://www.openwall.com/lists/oss-security/2023/01/16/8

  • Debian ships an almost unpatched copy, so is not affected by itself

  • Still tracking for the purpose of potential downstream providers

  • https://github.com/ARM-software/arm-trusted-firmware/commit/fd37982a19a4a291 (v2.9-rc0)

  • https://github.com/ARM-software/arm-trusted-firmware/commit/72460f50e2437a85 (v2.9-rc0)

  • https://github.com/ARM-software/arm-trusted-firmware/commit/f5c51855d36e399e (v2.9-rc0)

  • https://github.com/ARM-software/arm-trusted-firmware/commit/abb8f936fd0ad085 (v2.9-rc0)

EPSS

Процентиль: 68%
0.00579
Низкий

Связанные уязвимости

CVSS3: 7.4
ubuntu
около 3 лет назад

Trusted Firmware-A through 2.8 has an out-of-bounds read in the X.509 parser for parsing boot certificates. This affects downstream use of get_ext and auth_nvctr. Attackers might be able to trigger dangerous read side effects or obtain sensitive information about microarchitectural state.

CVSS3: 7.4
nvd
около 3 лет назад

Trusted Firmware-A through 2.8 has an out-of-bounds read in the X.509 parser for parsing boot certificates. This affects downstream use of get_ext and auth_nvctr. Attackers might be able to trigger dangerous read side effects or obtain sensitive information about microarchitectural state.

CVSS3: 7.4
github
около 3 лет назад

Trusted Firmware-A through 2.8 has an out-of-bounds read in the X.509 parser for parsing boot certificates. This affects downstream use of get_ext and auth_nvctr. Attackers might be able to trigger dangerous read side effects or obtain sensitive information about microarchitectural state.

EPSS

Процентиль: 68%
0.00579
Низкий