Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-24455

Опубликовано: 13 окт. 2020
Источник: redhat
CVSS3: 4.1

Описание

Missing initialization of a variable in the TPM2 source may allow a privileged user to potentially enable an escalation of privilege via local access. This affects tpm2-tss before 3.0.1 and before 2.4.3.

The tpm2-tss package introduced an implementation of TCG Feature API (FAPI) from v2.4.0. While instantiating TPM policy via FAPI, TPM's Platform Configuration Register (PCR) are used to compute policy digest. While reading PCR values via 'ifapi_read_pcr' routine, a PCR list counter was not set which can lead to an incorrect policy instantiation. This may potentially lead to a DoS scenario.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7tpm2-tssNot affected
Red Hat Enterprise Linux 8tpm2-tssNot affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-456
https://bugzilla.redhat.com/show_bug.cgi?id=1902167tpm2-tss: FAPI PolicyPCR not instatiating correctly

4.1 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.7
ubuntu
больше 5 лет назад

Missing initialization of a variable in the TPM2 source may allow a privileged user to potentially enable an escalation of privilege via local access. This affects tpm2-tss before 3.0.1 and before 2.4.3.

CVSS3: 6.7
nvd
больше 5 лет назад

Missing initialization of a variable in the TPM2 source may allow a privileged user to potentially enable an escalation of privilege via local access. This affects tpm2-tss before 3.0.1 and before 2.4.3.

CVSS3: 6.7
msrc
около 5 лет назад

Описание отсутствует

CVSS3: 6.7
debian
больше 5 лет назад

Missing initialization of a variable in the TPM2 source may allow a pr ...

CVSS3: 6.7
github
около 4 лет назад

Missing initialization of a variable in the TPM2 source may allow a privileged user to potentially enable an escalation of privilege via local access. This affects tpm2-tss before 3.0.1 and before 2.4.3.

4.1 Medium

CVSS3