Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-3569

Опубликовано: 23 мая 2020
Источник: redhat
CVSS3: 6.2
EPSS Низкий

Описание

A stack corruption bug was found in libtpms in versions before 0.7.2 and before 0.8.0 while decrypting data using RSA. This flaw could result in a SIGBUS (bad memory access) and termination of swtpm. The highest threat from this vulnerability is to system availability.

A stack corruption bug was found in libtpms while decrypting data using RSA. This flaw could result in a SIGBUS (bad memory access) and termination of swtpm. The highest threat from this vulnerability is to system availability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 8 Advanced Virtualizationvirt:8.2/libtpmsWill not fix
Red Hat Enterprise Linux 8 Advanced Virtualizationvirt:8.3/libtpmsNot affected
Red Hat Enterprise Linux 8 Advanced Virtualizationvirt:av/libtpmsNot affected
Red Hat Enterprise Linux 9libtpmsNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-120
https://bugzilla.redhat.com/show_bug.cgi?id=1964358libtpms: stack corruption bug in RSA decryption

EPSS

Процентиль: 15%
0.00047
Низкий

6.2 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 4 лет назад

A stack corruption bug was found in libtpms in versions before 0.7.2 and before 0.8.0 while decrypting data using RSA. This flaw could result in a SIGBUS (bad memory access) and termination of swtpm. The highest threat from this vulnerability is to system availability.

CVSS3: 5.5
nvd
больше 4 лет назад

A stack corruption bug was found in libtpms in versions before 0.7.2 and before 0.8.0 while decrypting data using RSA. This flaw could result in a SIGBUS (bad memory access) and termination of swtpm. The highest threat from this vulnerability is to system availability.

CVSS3: 5.5
debian
больше 4 лет назад

A stack corruption bug was found in libtpms in versions before 0.7.2 a ...

CVSS3: 5.5
github
больше 3 лет назад

A stack corruption bug was found in libtpms in versions before 0.7.2 and before 0.8.0 while decrypting data using RSA. This flaw could result in a SIGBUS (bad memory access) and termination of swtpm. The highest threat from this vulnerability is to system availability.

CVSS3: 5.5
fstec
больше 4 лет назад

Уязвимость библиотеки для обеспечивания программной эмуляции модуля Trusted Platform Module libtpms, связанная с выходом операции за границы буфера в памяти, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 15%
0.00047
Низкий

6.2 Medium

CVSS3