PT-2020-12551 · Usc Ilab+1 · Usc Ilab Cereal+1
Guidovranken
·
Published
2020-03-30
·
Updated
2024-04-20
·
CVE-2020-11104
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
USC iLab cereal versions 1.3.0 and earlier
Description
An issue was discovered in the serialization of an initialized C/C++ long double variable into a BinaryArchive or PortableBinaryArchive, which leaks several bytes of stack or heap memory. This can reveal sensitive information, such as memory layout or private keys, if the archive is distributed outside of a trusted context.
Recommendations
For versions 1.3.0 and earlier, consider restricting the distribution of archives to trusted contexts to minimize the risk of exploitation. As a temporary workaround, avoid serializing initialized C/C++ long double variables into BinaryArchive or PortableBinaryArchive until a patch is available.
Exploit
Fix
Use of Uninitialized Resource
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Usc Ilab Cereal