Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-29362

Опубликовано: 12 дек. 2020
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

An issue was discovered in p11-kit 0.21.1 through 0.23.21. A heap-based buffer over-read has been discovered in the RPC protocol used by thep11-kit server/remote commands and the client library. When the remote entity supplies a byte array through a serialized PKCS#11 function call, the receiving entity may allow the reading of up to 4 bytes of memory past the heap allocation.

Отчет

The p11-kit library is primarily intended to be used locally, in which case the attacker needs to have sufficient permission to access the p11-kit communication. Although there may be use cases of p11-kit being used with a remote entity, all parties must be considered trusted. As a result, Red Hat considers this vulnerability with a Medium severity.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6p11-kitNot affected
Red Hat Enterprise Linux 7p11-kitWill not fix
Red Hat Enterprise Linux 8p11-kitFixedRHSA-2021:160918.05.2021

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=1903590p11-kit: out-of-bounds read in p11_rpc_buffer_get_byte_array function in rpc-message.c

EPSS

Процентиль: 22%
0.0007
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
больше 4 лет назад

An issue was discovered in p11-kit 0.21.1 through 0.23.21. A heap-based buffer over-read has been discovered in the RPC protocol used by thep11-kit server/remote commands and the client library. When the remote entity supplies a byte array through a serialized PKCS#11 function call, the receiving entity may allow the reading of up to 4 bytes of memory past the heap allocation.

CVSS3: 5.3
nvd
больше 4 лет назад

An issue was discovered in p11-kit 0.21.1 through 0.23.21. A heap-based buffer over-read has been discovered in the RPC protocol used by thep11-kit server/remote commands and the client library. When the remote entity supplies a byte array through a serialized PKCS#11 function call, the receiving entity may allow the reading of up to 4 bytes of memory past the heap allocation.

CVSS3: 5.3
msrc
больше 4 лет назад

Описание отсутствует

CVSS3: 5.3
debian
больше 4 лет назад

An issue was discovered in p11-kit 0.21.1 through 0.23.21. A heap-base ...

suse-cvrf
почти 3 года назад

Security update for p11-kit

EPSS

Процентиль: 22%
0.0007
Низкий

5.3 Medium

CVSS3