Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2022-47630

Опубликовано: 16 янв. 2023
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 7.4

Описание

Trusted Firmware-A through 2.8 has an out-of-bounds read in the X.509 parser for parsing boot certificates. This affects downstream use of get_ext and auth_nvctr. Attackers might be able to trigger dangerous read side effects or obtain sensitive information about microarchitectural state.

РелизСтатусПримечание
bionic

DNE

devel

needed

esm-apps/focal

needed

esm-apps/jammy

needed

esm-apps/noble

needed

focal

ignored

end of standard support, was needed
jammy

needed

kinetic

ignored

end of life, was needed
lunar

ignored

end of life, was needed
mantic

ignored

end of life, was needed

Показывать по

EPSS

Процентиль: 68%
0.00579
Низкий

7.4 High

CVSS3

Связанные уязвимости

CVSS3: 7.4
nvd
около 3 лет назад

Trusted Firmware-A through 2.8 has an out-of-bounds read in the X.509 parser for parsing boot certificates. This affects downstream use of get_ext and auth_nvctr. Attackers might be able to trigger dangerous read side effects or obtain sensitive information about microarchitectural state.

CVSS3: 7.4
debian
около 3 лет назад

Trusted Firmware-A through 2.8 has an out-of-bounds read in the X.509 ...

CVSS3: 7.4
github
около 3 лет назад

Trusted Firmware-A through 2.8 has an out-of-bounds read in the X.509 parser for parsing boot certificates. This affects downstream use of get_ext and auth_nvctr. Attackers might be able to trigger dangerous read side effects or obtain sensitive information about microarchitectural state.

EPSS

Процентиль: 68%
0.00579
Низкий

7.4 High

CVSS3