Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2024-9424

Опубликовано: 14 нояб. 2024
Источник: oracle-oval
Платформа: Oracle Linux 9

Описание

ELSA-2024-9424: tpm2-tools security update (LOW)

[5.2-4]

  • Backport upstream fixes.
  • tpm2_checkquote: Fix check of magic number. (CVE-2024-29038)
  • tpm2_checkquote: Add comparison of pcr selection. (CVE-2024-29039)
  • Fix check of magic number. Resolves: RHEL-23198 Resolves: RHEL-41031 Resolves: RHEL-41035

Обновленные пакеты

Oracle Linux 9

Oracle Linux aarch64

tpm2-tools

5.2-4.el9

Oracle Linux x86_64

tpm2-tools

5.2-4.el9

Связанные CVE

Связанные уязвимости

suse-cvrf
около 1 года назад

Security update for tpm2.0-tools

CVSS3: 4.3
ubuntu
около 1 года назад

tpm2-tools is the source repository for the Trusted Platform Module (TPM2.0) tools. A malicious attacker can generate arbitrary quote data which is not detected by `tpm2 checkquote`. This issue was patched in version 5.7.

CVSS3: 4.4
redhat
около 1 года назад

tpm2-tools is the source repository for the Trusted Platform Module (TPM2.0) tools. A malicious attacker can generate arbitrary quote data which is not detected by `tpm2 checkquote`. This issue was patched in version 5.7.

CVSS3: 4.3
nvd
около 1 года назад

tpm2-tools is the source repository for the Trusted Platform Module (TPM2.0) tools. A malicious attacker can generate arbitrary quote data which is not detected by `tpm2 checkquote`. This issue was patched in version 5.7.

CVSS3: 4.3
msrc
11 месяцев назад

Описание отсутствует

Уязвимость ELSA-2024-9424