PT-2020-12551 · Usc Ilab+1 · Usc Ilab Cereal+1

Guidovranken

·

Published

2020-03-30

·

Updated

2024-04-20

·

CVE-2020-11104

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions USC iLab cereal versions 1.3.0 and earlier
Description An issue was discovered in the serialization of an initialized C/C++ long double variable into a BinaryArchive or PortableBinaryArchive, which leaks several bytes of stack or heap memory. This can reveal sensitive information, such as memory layout or private keys, if the archive is distributed outside of a trusted context.
Recommendations For versions 1.3.0 and earlier, consider restricting the distribution of archives to trusted contexts to minimize the risk of exploitation. As a temporary workaround, avoid serializing initialized C/C++ long double variables into BinaryArchive or PortableBinaryArchive until a patch is available.

Exploit

Fix

Use of Uninitialized Resource

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2024-6878
CVE-2020-11104

Affected Products

Alt Linux
Usc Ilab Cereal