CVE-2020-29363: Buffer Overflow
An issue was discovered in p11-kit 0.23.6 through 0.23.21. A heap-based buffer overflow has been discovered in the RPC protocol used by p11-kit server/remote commands and the client library. When the remote entity supplies a serialized byte array in a CKATTRIBUTE, the receiving entity may not allocate sufficient length for the buffer to store the deserialized value.
Other sources
p11-glue p11-kit is vulnerable to a denial of service, caused by a heap-based buffer overflow in the RPC protocol. By sending a serialized byte array in a CKATTRIBUTE, a remote attacker could overflow a buffer and cause a denial of service.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2020-29363?
CVE-2020-29363 is a vulnerability in p11-glue p11-kit that can lead to a denial of service caused by a heap-based buffer overflow.
How does CVE-2020-29363 affect p11-kit?
CVE-2020-29363 affects p11-kit versions 0.23.6 through 0.23.21 and can be exploited through the RPC protocol used by p11-kit server/remote commands and the client library.
What is the severity of CVE-2020-29363?
CVE-2020-29363 has a severity rating of 7.5 (High).
Which software versions are affected by CVE-2020-29363?
CVE-2020-29363 affects p11-kit versions 0.23.6 through 0.23.21, and Cloud Pak for Security (CP4S) versions up to and including 1.7.2.0.
How can I fix CVE-2020-29363?
To fix CVE-2020-29363, update p11-kit to versions 0.23.22 or later, or the affected software to a version that includes the necessary security patches.