Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-99cg-575x-774p

Опубликовано: 01 фев. 2022
Источник: github
Github: Прошло ревью
CVSS3: 4

Описание

Go-Attestation Improper Input Validation with attacker-controlled TPM Quote

Impact

An improper input validation vulnerability in go-attestation before 0.4.0 allows local users to provide a maliciously-formed Quote over no/some PCRs, causing AKPublic.Verify to succeed despite the inconsistency. Subsequent use of the same set of PCR values in Eventlog.Verify lacks the authentication performed by quote verification, meaning a local attacker could couple this vulnerability with a maliciously-crafted TCG log in Eventlog.Verify to spoof events in the TCG log, hence defeating remotely-attested measured-boot.

Patches

This issue is resolved in version 0.4.0. If your usage of this library verifies PCRs using multiple quotes, make sure to use the new method AKPublic.VerifyAll() instead of AKPublic.Verify.

Пакеты

Наименование

github.com/google/go-attestation

go
Затронутые версииВерсия исправления

< 0.4.0

0.4.0

EPSS

Процентиль: 3%
0.00017
Низкий

4 Medium

CVSS3

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 4
nvd
около 4 лет назад

An improper input validation vulnerability in go-attestation before 0.3.3 allows local users to provide a maliciously-formed Quote over no/some PCRs, causing AKPublic.Verify to succeed despite the inconsistency. Subsequent use of the same set of PCR values in Eventlog.Verify lacks the authentication performed by quote verification, meaning a local attacker could couple this vulnerability with a maliciously-crafted TCG log in Eventlog.Verify to spoof events in the TCG log, hence defeating remotely-attested measured-boot. We recommend upgrading to Version 0.4.0 or above.

EPSS

Процентиль: 3%
0.00017
Низкий

4 Medium

CVSS3

Дефекты

CWE-20