Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qx3f-hv27-2wg9

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

In Linaro OP-TEE before 3.7.0, by using inconsistent or malformed data, it is possible to call update and final cryptographic functions directly, causing a crash that could leak sensitive information.

In Linaro OP-TEE before 3.7.0, by using inconsistent or malformed data, it is possible to call update and final cryptographic functions directly, causing a crash that could leak sensitive information.

EPSS

Процентиль: 42%
0.00203
Низкий

Дефекты

CWE-327

Связанные уязвимости

CVSS3: 9.1
nvd
больше 4 лет назад

In Linaro OP-TEE before 3.7.0, by using inconsistent or malformed data, it is possible to call update and final cryptographic functions directly, causing a crash that could leak sensitive information.

CVSS3: 9.1
debian
больше 4 лет назад

In Linaro OP-TEE before 3.7.0, by using inconsistent or malformed data ...

EPSS

Процентиль: 42%
0.00203
Низкий

Дефекты

CWE-327