Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-29038

Опубликовано: 30 апр. 2024
Источник: redhat
CVSS3: 4.4

Описание

tpm2-tools is the source repository for the Trusted Platform Module (TPM2.0) tools. A malicious attacker can generate arbitrary quote data which is not detected by tpm2 checkquote. This issue was patched in version 5.7.

A flaw was found in the tpm2-tools package. This issue occurs due to a missing check whether the magic number in attest is equal to TPM2_GENERATED_VALUE, which can allow an attacker to generate arbitrary quote data that may not be detected by tpm2_checkquote.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7tpm2-toolsOut of support scope
Red Hat Enterprise Linux 8tpm2-toolsFix deferred
Red Hat Enterprise Linux 9tpm2-toolsFixedRHSA-2024:942412.11.2024
Red Hat Enterprise Linux 9tpm2-toolsFixedRHSA-2024:942412.11.2024

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-20
https://bugzilla.redhat.com/show_bug.cgi?id=2278071tpm2-tools: arbitrary quote data may go undetected by tpm2_checkquote

4.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.3
ubuntu
около 1 года назад

tpm2-tools is the source repository for the Trusted Platform Module (TPM2.0) tools. A malicious attacker can generate arbitrary quote data which is not detected by `tpm2 checkquote`. This issue was patched in version 5.7.

CVSS3: 4.3
nvd
около 1 года назад

tpm2-tools is the source repository for the Trusted Platform Module (TPM2.0) tools. A malicious attacker can generate arbitrary quote data which is not detected by `tpm2 checkquote`. This issue was patched in version 5.7.

CVSS3: 4.3
msrc
11 месяцев назад

Описание отсутствует

CVSS3: 4.3
debian
около 1 года назад

tpm2-tools is the source repository for the Trusted Platform Module (T ...

suse-cvrf
около 1 года назад

Security update for tpm2.0-tools

4.4 Medium

CVSS3