CVE-2020-29362: Medium severity ibm cloud pak for security vulnerability
An issue was discovered in p11-kit 0.21.1 through 0.23.21. A heap-based buffer over-read has been discovered in the RPC protocol used by thep11-kit server/remote commands and the client library. When the remote entity supplies a byte array through a serialized PKCS#11 function call, the receiving entity may allow the reading of up to 4 bytes of memory past the heap allocation.
Other sources
p11-glue p11-kit could allow a remote attacker to obtain sensitive information, caused by a heap-based buffer over-read flaw in the RPC protocol. By sending a specially-crafted request, an attacker could exploit this vulnerability to obtain up to 4 bytes of memory past the heap allocation, and use this information to launch further attacks against the affected system.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-29362?
CVE-2020-29362 is a vulnerability discovered in p11-kit, allowing a remote attacker to obtain sensitive information.
What is the severity of CVE-2020-29362?
The severity of CVE-2020-29362 is medium with a CVSS score of 5.3.
How does CVE-2020-29362 affect p11-kit?
CVE-2020-29362 affects p11-kit versions 0.21.1 through 0.23.21.
How can the vulnerability CVE-2020-29362 be exploited?
CVE-2020-29362 can be exploited by a remote attacker through the RPC protocol used by the p11-kit server/remote commands and the client library.
Is there a fix available for CVE-2020-29362?
Yes, fixes are available for CVE-2020-29362. Please update to p11-kit versions 0.23.15-2+deb10u1, 0.23.22-1, 0.24.1-2, or 0.25.0-5.