Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2021-3505

Опубликовано: 19 апр. 2021
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS2: 2.1
CVSS3: 5.5

Описание

A flaw was found in libtpms in versions before 0.8.0. The TPM 2 implementation returns 2048 bit keys with ~1984 bit strength due to a bug in the TCG specification. The bug is in the key creation algorithm in RsaAdjustPrimeCandidate(), which is called before the prime number check. The highest threat from this vulnerability is to data confidentiality.

РелизСтатусПримечание
bionic

DNE

devel

not-affected

esm-infra-legacy/trusty

DNE

esm-infra/focal

DNE

focal

DNE

groovy

not-affected

0.8.0~dev1-1.1
precise/esm

DNE

trusty

ignored

end of standard support
trusty/esm

DNE

upstream

released

0.8.0~dev1-1

Показывать по

EPSS

Процентиль: 33%
0.00126
Низкий

2.1 Low

CVSS2

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 4
redhat
больше 5 лет назад

A flaw was found in libtpms in versions before 0.8.0. The TPM 2 implementation returns 2048 bit keys with ~1984 bit strength due to a bug in the TCG specification. The bug is in the key creation algorithm in RsaAdjustPrimeCandidate(), which is called before the prime number check. The highest threat from this vulnerability is to data confidentiality.

CVSS3: 5.5
nvd
больше 4 лет назад

A flaw was found in libtpms in versions before 0.8.0. The TPM 2 implementation returns 2048 bit keys with ~1984 bit strength due to a bug in the TCG specification. The bug is in the key creation algorithm in RsaAdjustPrimeCandidate(), which is called before the prime number check. The highest threat from this vulnerability is to data confidentiality.

CVSS3: 5.5
debian
больше 4 лет назад

A flaw was found in libtpms in versions before 0.8.0. The TPM 2 implem ...

github
около 3 лет назад

A flaw was found in libtpms in versions before 0.8.0. The TPM 2 implementation returns 2048 bit keys with ~1984 bit strength due to a bug in the TCG specification. The bug is in the key creation algorithm in RsaAdjustPrimeCandidate(), which is called before the prime number check. The highest threat from this vulnerability is to data confidentiality.

EPSS

Процентиль: 33%
0.00126
Низкий

2.1 Low

CVSS2

5.5 Medium

CVSS3