Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-10759

Опубликовано: 05 июн. 2020
Источник: redhat
CVSS3: 5.7

Описание

A PGP signature bypass flaw was found in fwupd (all versions), which could lead to the installation of unsigned firmware. As per upstream, a signature bypass is theoretically possible, but not practical because the Linux Vendor Firmware Service (LVFS) is either not implemented or enabled in versions of fwupd shipped with Red Hat Enterprise Linux 7 and 8. The highest threat from this vulnerability is to confidentiality and integrity.

A PGP signature bypass flaw was found in fwupd, which could lead to the installation of unsigned firmware. As per upstream, a signature bypass is theoretically possible, but not practical because the Linux Vendor Firmware Service (LVFS) is either not implemented or enabled in versions of fwupd shipped with Red Hat Enterprise Linux 7 and 8. The highest threat from this vulnerability is to confidentiality and integrity.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7fwupdFix deferred
Red Hat Enterprise Linux 8appstream-dataFixedRHSA-2020:443604.11.2020
Red Hat Enterprise Linux 8fwupdFixedRHSA-2020:443604.11.2020
Red Hat Enterprise Linux 8gnome-softwareFixedRHSA-2020:443604.11.2020
Red Hat Enterprise Linux 8libxmlbFixedRHSA-2020:443604.11.2020
Red Hat Enterprise Linux 8appstream-dataFixedRHSA-2020:443604.11.2020
Red Hat Enterprise Linux 8fwupdFixedRHSA-2020:443604.11.2020
Red Hat Enterprise Linux 8gnome-softwareFixedRHSA-2020:443604.11.2020
Red Hat Enterprise Linux 8libxmlbFixedRHSA-2020:443604.11.2020

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-347
https://bugzilla.redhat.com/show_bug.cgi?id=1844316fwupd: Possible bypass in signature verification

5.7 Medium

CVSS3

Связанные уязвимости

CVSS3: 6
ubuntu
почти 5 лет назад

A PGP signature bypass flaw was found in fwupd (all versions), which could lead to the installation of unsigned firmware. As per upstream, a signature bypass is theoretically possible, but not practical because the Linux Vendor Firmware Service (LVFS) is either not implemented or enabled in versions of fwupd shipped with Red Hat Enterprise Linux 7 and 8. The highest threat from this vulnerability is to confidentiality and integrity.

CVSS3: 6
nvd
почти 5 лет назад

A PGP signature bypass flaw was found in fwupd (all versions), which could lead to the installation of unsigned firmware. As per upstream, a signature bypass is theoretically possible, but not practical because the Linux Vendor Firmware Service (LVFS) is either not implemented or enabled in versions of fwupd shipped with Red Hat Enterprise Linux 7 and 8. The highest threat from this vulnerability is to confidentiality and integrity.

CVSS3: 6
debian
почти 5 лет назад

A PGP signature bypass flaw was found in fwupd (all versions), which c ...

suse-cvrf
около 4 лет назад

Security update for fwupd

suse-cvrf
почти 5 лет назад

Security update for fwupd

5.7 Medium

CVSS3