Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-24455

Опубликовано: 13 окт. 2020
Источник: redhat
CVSS3: 4.1
EPSS Низкий

Описание

Missing initialization of a variable in the TPM2 source may allow a privileged user to potentially enable an escalation of privilege via local access. This affects tpm2-tss before 3.0.1 and before 2.4.3.

The tpm2-tss package introduced an implementation of TCG Feature API (FAPI) from v2.4.0. While instantiating TPM policy via FAPI, TPM's Platform Configuration Register (PCR) are used to compute policy digest. While reading PCR values via 'ifapi_read_pcr' routine, a PCR list counter was not set which can lead to an incorrect policy instantiation. This may potentially lead to a DoS scenario.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7tpm2-tssNot affected
Red Hat Enterprise Linux 8tpm2-tssNot affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-456
https://bugzilla.redhat.com/show_bug.cgi?id=1902167tpm2-tss: FAPI PolicyPCR not instatiating correctly

EPSS

Процентиль: 28%
0.00101
Низкий

4.1 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.7
ubuntu
почти 5 лет назад

Missing initialization of a variable in the TPM2 source may allow a privileged user to potentially enable an escalation of privilege via local access. This affects tpm2-tss before 3.0.1 and before 2.4.3.

CVSS3: 6.7
nvd
почти 5 лет назад

Missing initialization of a variable in the TPM2 source may allow a privileged user to potentially enable an escalation of privilege via local access. This affects tpm2-tss before 3.0.1 and before 2.4.3.

CVSS3: 6.7
msrc
больше 4 лет назад

Описание отсутствует

CVSS3: 6.7
debian
почти 5 лет назад

Missing initialization of a variable in the TPM2 source may allow a pr ...

CVSS3: 6.7
github
больше 3 лет назад

Missing initialization of a variable in the TPM2 source may allow a privileged user to potentially enable an escalation of privilege via local access. This affects tpm2-tss before 3.0.1 and before 2.4.3.

EPSS

Процентиль: 28%
0.00101
Низкий

4.1 Medium

CVSS3