Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 11

Количество 11

ubuntu логотип

CVE-2023-22745

больше 3 лет назад

tpm2-tss is an open source software implementation of the Trusted Computing Group (TCG) Trusted Platform Module (TPM) 2 Software Stack (TSS2). In versions prior to 4.1.0-rc0, 4.0.1, and 3.2.2-rc1, `Tss2_RC_SetHandler` and `Tss2_RC_Decode` both index into `layer_handler` with an 8 bit layer number, but the array only has `TPM2_ERROR_TSS2_RC_LAYER_COUNT` entries, so trying to add a handler for higher-numbered layers or decode a response code with such a layer number reads/writes past the end of the buffer. This Buffer overrun, could result in arbitrary code execution. An example attack would be a MiTM bus attack that returns 0xFFFFFFFF for the RC. Given the common use case of TPM modules an attacker must have local access to the target machine with local system privileges which allows access to the TPM system. Usually TPM access requires administrative privilege. Versions 4.1.0-rc0, 4.0.1, and 3.2.2-rc1 fix the issue.

CVSS3: 6.4
EPSS: Низкий
redhat логотип

CVE-2023-22745

больше 3 лет назад

tpm2-tss is an open source software implementation of the Trusted Computing Group (TCG) Trusted Platform Module (TPM) 2 Software Stack (TSS2). In versions prior to 4.1.0-rc0, 4.0.1, and 3.2.2-rc1, `Tss2_RC_SetHandler` and `Tss2_RC_Decode` both index into `layer_handler` with an 8 bit layer number, but the array only has `TPM2_ERROR_TSS2_RC_LAYER_COUNT` entries, so trying to add a handler for higher-numbered layers or decode a response code with such a layer number reads/writes past the end of the buffer. This Buffer overrun, could result in arbitrary code execution. An example attack would be a MiTM bus attack that returns 0xFFFFFFFF for the RC. Given the common use case of TPM modules an attacker must have local access to the target machine with local system privileges which allows access to the TPM system. Usually TPM access requires administrative privilege. Versions 4.1.0-rc0, 4.0.1, and 3.2.2-rc1 fix the issue.

CVSS3: 6.4
EPSS: Низкий
nvd логотип

CVE-2023-22745

больше 3 лет назад

tpm2-tss is an open source software implementation of the Trusted Computing Group (TCG) Trusted Platform Module (TPM) 2 Software Stack (TSS2). In versions prior to 4.1.0-rc0, 4.0.1, and 3.2.2-rc1, `Tss2_RC_SetHandler` and `Tss2_RC_Decode` both index into `layer_handler` with an 8 bit layer number, but the array only has `TPM2_ERROR_TSS2_RC_LAYER_COUNT` entries, so trying to add a handler for higher-numbered layers or decode a response code with such a layer number reads/writes past the end of the buffer. This Buffer overrun, could result in arbitrary code execution. An example attack would be a MiTM bus attack that returns 0xFFFFFFFF for the RC. Given the common use case of TPM modules an attacker must have local access to the target machine with local system privileges which allows access to the TPM system. Usually TPM access requires administrative privilege. Versions 4.1.0-rc0, 4.0.1, and 3.2.2-rc1 fix the issue.

CVSS3: 6.4
EPSS: Низкий
msrc логотип

CVE-2023-22745

больше 3 лет назад

Buffer Overlow in TSS2_RC_Decode in tpm2-tss

CVSS3: 6.4
EPSS: Низкий
debian логотип

CVE-2023-22745

больше 3 лет назад

tpm2-tss is an open source software implementation of the Trusted Comp ...

CVSS3: 6.4
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:0613-1

больше 3 лет назад

Security update for tpm2-0-tss

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:0526-1

больше 3 лет назад

Security update for tpm2-0-tss

EPSS: Низкий
oracle-oval логотип

ELSA-2023-7166

больше 2 лет назад

ELSA-2023-7166: tpm2-tss security and enhancement update (LOW)

EPSS: Низкий
oracle-oval логотип

ELSA-2023-6685

больше 2 лет назад

ELSA-2023-6685: tpm2-tss security and enhancement update (LOW)

EPSS: Низкий
fstec логотип

BDU:2023-07640

больше 3 лет назад

Уязвимость функций Tss2_RC_Decode и Tss2_RC_SetHandler реализации TCG TPM2 TPM2 Software Stack, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании

CVSS3: 6.4
EPSS: Низкий
redos логотип

ROS-20240611-02

около 2 лет назад

Множественные уязвимости tpm2-tss

CVSS3: 6.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2023-22745

tpm2-tss is an open source software implementation of the Trusted Computing Group (TCG) Trusted Platform Module (TPM) 2 Software Stack (TSS2). In versions prior to 4.1.0-rc0, 4.0.1, and 3.2.2-rc1, `Tss2_RC_SetHandler` and `Tss2_RC_Decode` both index into `layer_handler` with an 8 bit layer number, but the array only has `TPM2_ERROR_TSS2_RC_LAYER_COUNT` entries, so trying to add a handler for higher-numbered layers or decode a response code with such a layer number reads/writes past the end of the buffer. This Buffer overrun, could result in arbitrary code execution. An example attack would be a MiTM bus attack that returns 0xFFFFFFFF for the RC. Given the common use case of TPM modules an attacker must have local access to the target machine with local system privileges which allows access to the TPM system. Usually TPM access requires administrative privilege. Versions 4.1.0-rc0, 4.0.1, and 3.2.2-rc1 fix the issue.

CVSS3: 6.4
1%
Низкий
больше 3 лет назад
redhat логотип
CVE-2023-22745

tpm2-tss is an open source software implementation of the Trusted Computing Group (TCG) Trusted Platform Module (TPM) 2 Software Stack (TSS2). In versions prior to 4.1.0-rc0, 4.0.1, and 3.2.2-rc1, `Tss2_RC_SetHandler` and `Tss2_RC_Decode` both index into `layer_handler` with an 8 bit layer number, but the array only has `TPM2_ERROR_TSS2_RC_LAYER_COUNT` entries, so trying to add a handler for higher-numbered layers or decode a response code with such a layer number reads/writes past the end of the buffer. This Buffer overrun, could result in arbitrary code execution. An example attack would be a MiTM bus attack that returns 0xFFFFFFFF for the RC. Given the common use case of TPM modules an attacker must have local access to the target machine with local system privileges which allows access to the TPM system. Usually TPM access requires administrative privilege. Versions 4.1.0-rc0, 4.0.1, and 3.2.2-rc1 fix the issue.

CVSS3: 6.4
1%
Низкий
больше 3 лет назад
nvd логотип
CVE-2023-22745

tpm2-tss is an open source software implementation of the Trusted Computing Group (TCG) Trusted Platform Module (TPM) 2 Software Stack (TSS2). In versions prior to 4.1.0-rc0, 4.0.1, and 3.2.2-rc1, `Tss2_RC_SetHandler` and `Tss2_RC_Decode` both index into `layer_handler` with an 8 bit layer number, but the array only has `TPM2_ERROR_TSS2_RC_LAYER_COUNT` entries, so trying to add a handler for higher-numbered layers or decode a response code with such a layer number reads/writes past the end of the buffer. This Buffer overrun, could result in arbitrary code execution. An example attack would be a MiTM bus attack that returns 0xFFFFFFFF for the RC. Given the common use case of TPM modules an attacker must have local access to the target machine with local system privileges which allows access to the TPM system. Usually TPM access requires administrative privilege. Versions 4.1.0-rc0, 4.0.1, and 3.2.2-rc1 fix the issue.

CVSS3: 6.4
1%
Низкий
больше 3 лет назад
msrc логотип
CVE-2023-22745

Buffer Overlow in TSS2_RC_Decode in tpm2-tss

CVSS3: 6.4
1%
Низкий
больше 3 лет назад
debian логотип
CVE-2023-22745

tpm2-tss is an open source software implementation of the Trusted Comp ...

CVSS3: 6.4
1%
Низкий
больше 3 лет назад
suse-cvrf логотип
SUSE-SU-2023:0613-1

Security update for tpm2-0-tss

1%
Низкий
больше 3 лет назад
suse-cvrf логотип
SUSE-SU-2023:0526-1

Security update for tpm2-0-tss

1%
Низкий
больше 3 лет назад
oracle-oval логотип
ELSA-2023-7166

ELSA-2023-7166: tpm2-tss security and enhancement update (LOW)

больше 2 лет назад
oracle-oval логотип
ELSA-2023-6685

ELSA-2023-6685: tpm2-tss security and enhancement update (LOW)

больше 2 лет назад
fstec логотип
BDU:2023-07640

Уязвимость функций Tss2_RC_Decode и Tss2_RC_SetHandler реализации TCG TPM2 TPM2 Software Stack, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании

CVSS3: 6.4
1%
Низкий
больше 3 лет назад
redos логотип
ROS-20240611-02

Множественные уязвимости tpm2-tss

CVSS3: 6.4
около 2 лет назад

Уязвимостей на страницу