Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2020-10759

Опубликовано: 15 сент. 2020
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 3.3
CVSS3: 6

Описание

A PGP signature bypass flaw was found in fwupd (all versions), which could lead to the installation of unsigned firmware. As per upstream, a signature bypass is theoretically possible, but not practical because the Linux Vendor Firmware Service (LVFS) is either not implemented or enabled in versions of fwupd shipped with Red Hat Enterprise Linux 7 and 8. The highest threat from this vulnerability is to confidentiality and integrity.

РелизСтатусПримечание
bionic

released

1.2.10-1ubuntu2~ubuntu18.04.5
devel

released

1.3.10-1
eoan

released

1.2.10-1ubuntu4.1
esm-infra-legacy/trusty

DNE

esm-infra/bionic

not-affected

1.2.10-1ubuntu2~ubuntu18.04.5
esm-infra/focal

not-affected

1.3.9-4ubuntu0.1
esm-infra/xenial

not-affected

0.8.3-0ubuntu5.1
focal

released

1.3.9-4ubuntu0.1
groovy

released

1.3.10-1
hirsute

released

1.3.10-1

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

not-affected

0.1.3-1
eoan

DNE

esm-apps/focal

not-affected

0.1.3-1
esm-infra-legacy/trusty

DNE

focal

not-affected

0.1.3-1
groovy

not-affected

0.1.3-1
hirsute

not-affected

0.1.3-1
impish

not-affected

0.1.3-1
jammy

not-affected

0.1.3-1

Показывать по

EPSS

Процентиль: 4%
0.00021
Низкий

3.3 Low

CVSS2

6 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.7
redhat
около 5 лет назад

A PGP signature bypass flaw was found in fwupd (all versions), which could lead to the installation of unsigned firmware. As per upstream, a signature bypass is theoretically possible, but not practical because the Linux Vendor Firmware Service (LVFS) is either not implemented or enabled in versions of fwupd shipped with Red Hat Enterprise Linux 7 and 8. The highest threat from this vulnerability is to confidentiality and integrity.

CVSS3: 6
nvd
почти 5 лет назад

A PGP signature bypass flaw was found in fwupd (all versions), which could lead to the installation of unsigned firmware. As per upstream, a signature bypass is theoretically possible, but not practical because the Linux Vendor Firmware Service (LVFS) is either not implemented or enabled in versions of fwupd shipped with Red Hat Enterprise Linux 7 and 8. The highest threat from this vulnerability is to confidentiality and integrity.

CVSS3: 6
debian
почти 5 лет назад

A PGP signature bypass flaw was found in fwupd (all versions), which c ...

suse-cvrf
около 4 лет назад

Security update for fwupd

suse-cvrf
почти 5 лет назад

Security update for fwupd

EPSS

Процентиль: 4%
0.00021
Низкий

3.3 Low

CVSS2

6 Medium

CVSS3