PT-2020-6233 · P11 Kit+8 · P11-Kit+8

David Cook

·

Published

2020-12-16

·

Updated

2023-01-04

·

CVE-2020-29362

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions p11-kit versions 0.21.1 through 0.23.21
Description A heap-based buffer over-read has been discovered in the RPC protocol used by the p11-kit server/remote commands and the client library. When the remote entity supplies a byte array through a serialized PKCS#11 function call, the receiving entity may allow the reading of up to 4 bytes of memory past the heap allocation. This issue is related to the p11 rpc buffer get byte array function and may allow a remote attacker to access confidential data.
Recommendations For p11-kit versions 0.21.1 through 0.23.21, consider disabling the p11 rpc buffer get byte array function until a patch is available to prevent potential exploitation. Restrict access to the RPC protocol used by the p11-kit server/remote commands and the client library to minimize the risk of exploitation. Avoid using the byte array parameter in the affected PKCS#11 function call until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Out of bounds Read

Weakness Enumeration

Related Identifiers

ALSA-2021:1609
ALT-PU-2022-1076
ALT-PU-2022-2435
ALT-PU-2023-1006
BDU:2021-03634
CESA-2021_1609
CVE-2020-29362
DLA-2513-1
DSA-4822-1
GHSA-5WPQ-43J2-6QWC
MGASA-2021-0041
OESA-2021-1024
OPENSUSE-SU-2022_2405-1
RHSA-2021:1609
RHSA-2021_1609
RLSA-2021:1609
SUSE-SU-2022:2405-1
SUSE-SU-2022:2405-2
SUSE-SU-2022:2871-1
SUSE-SU-2022_2405-1
SUSE-SU-2022_2871-1
USN-4677-1

Affected Products

Alt Linux
Almalinux
Centos
Linuxmint
Red Hat
Rocky Linux
Suse
Ubuntu
P11-Kit