Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-28407

Опубликовано: 14 нояб. 2020
Источник: redhat
CVSS3: 7.3

Описание

In swtpm before 0.4.2 and 0.5.x before 0.5.1, a local attacker may be able to overwrite arbitrary files via a symlink attack against a temporary file such as TMP2-00.permall.

A flaw was found in swtpm. This flaw allows an attacker to create a symbolic link with the name of the temporary file (TMP2-00.permall for TPM 2) and have this point to a valuable file, which will get overwritten by swtpm. The success of the attack depends on the attacker having access to the TPM's state directory (--tpmstate dir). The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 8 Advanced Virtualizationvirt:8.2/swtpmWill not fix
Red Hat Enterprise Linux 8 Advanced Virtualizationvirt:8.3/swtpmNot affected
Red Hat Enterprise Linux 8 Advanced Virtualizationvirt:av/swtpmNot affected
Red Hat Enterprise Linux 9swtpmNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-59
https://bugzilla.redhat.com/show_bug.cgi?id=1964465swtpm: symlink issue may lead to privilege escalation

7.3 High

CVSS3

Связанные уязвимости

CVSS3: 7.1
ubuntu
больше 2 лет назад

In swtpm before 0.4.2 and 0.5.x before 0.5.1, a local attacker may be able to overwrite arbitrary files via a symlink attack against a temporary file such as TMP2-00.permall.

CVSS3: 7.1
nvd
больше 2 лет назад

In swtpm before 0.4.2 and 0.5.x before 0.5.1, a local attacker may be able to overwrite arbitrary files via a symlink attack against a temporary file such as TMP2-00.permall.

CVSS3: 7.1
debian
больше 2 лет назад

In swtpm before 0.4.2 and 0.5.x before 0.5.1, a local attacker may be ...

CVSS3: 7.1
github
больше 2 лет назад

In swtpm before 0.4.2 and 0.5.x before 0.5.1, a local attacker may be able to overwrite arbitrary files via a symlink attack against a temporary file such as TMP2-00.permall.

7.3 High

CVSS3