Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Fishilicoo

#45336of 53,624
5.5Total CVSS
Vulnerabilities · 1
PT-2021-20813
5.5
2021-04-19
Libtpms · Libtpms · CVE-2021-3505
Name of the Vulnerable Software and Affected Versions: libtpms versions prior to 0.8.0 Description: A flaw was found in the TPM 2 implementation of libtpms, where it returns 2048 bit keys with approximately 1984 bit strength due to a bug in the TCG specification. The issue lies in the key creation algorithm, specifically in the RsaAdjustPrimeCandidate() function, which is called before the prime number check. This poses a significant threat to data confidentiality. Recommendations: For versions prior to 0.8.0, update to version 0.8.0 or later to resolve the issue.