PT-2020-6233 · P11 Kit+8 · P11-Kit+8
David Cook
·
Published
2020-12-16
·
Updated
2023-01-04
·
CVE-2020-29362
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
p11-kit versions 0.21.1 through 0.23.21
Description
A heap-based buffer over-read has been discovered in the RPC protocol used by the p11-kit server/remote commands and the client library. When the remote entity supplies a byte array through a serialized PKCS#11 function call, the receiving entity may allow the reading of up to 4 bytes of memory past the heap allocation. This issue is related to the
p11 rpc buffer get byte array function and may allow a remote attacker to access confidential data.Recommendations
For p11-kit versions 0.21.1 through 0.23.21, consider disabling the
p11 rpc buffer get byte array function until a patch is available to prevent potential exploitation. Restrict access to the RPC protocol used by the p11-kit server/remote commands and the client library to minimize the risk of exploitation. Avoid using the byte array parameter in the affected PKCS#11 function call until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Almalinux
Centos
Linuxmint
Red Hat
Rocky Linux
Suse
Ubuntu
P11-Kit