Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-chcf-c8w2-7x53

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Trusty contains a vulnerability in all TAs whose deserializer does not reject messages with multiple occurrences of the same parameter. The deserialization of untrusted data might allow an attacker to exploit the deserializer to impact code execution.

Trusty contains a vulnerability in all TAs whose deserializer does not reject messages with multiple occurrences of the same parameter. The deserialization of untrusted data might allow an attacker to exploit the deserializer to impact code execution.

EPSS

Процентиль: 30%
0.00112
Низкий

Дефекты

CWE-502

Связанные уязвимости

CVSS3: 4.2
nvd
больше 4 лет назад

Trusty contains a vulnerability in the NVIDIA OTE protocol that is present in all TAs. An incorrect message stream deserialization allows an attacker to use the malicious CA that is run by the user to cause the buffer overflow, which may lead to information disclosure and data modification.

EPSS

Процентиль: 30%
0.00112
Низкий

Дефекты

CWE-502