[Forgot Password]
Login  Register Subscribe

30480

 
 

423868

 
 

253164

 
 

909

 
 

197077

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS2-2021-1601 --- p11-kit

ID: oval:org.secpod.oval:def:1700560Date: (C)2021-02-22   (M)2023-12-20
Class: PATCHFamily: unix




An issue was discovered in p11-kit 0.21.1 through 0.23.21. Multiple integer overflows have been discovered in the array allocations in the p11-kit library and the p11-kit list command, where overflow checks are missing before calling realloc or calloc. An issue was discovered in p11-kit 0.21.1 through 0.23.21. A heap-based buffer over-read has been discovered in the RPC protocol used by thep11-kit server/remote commands and the client library. When the remote entity supplies a byte array through a serialized PKCS#11 function call, the receiving entity may allow the reading of up to 4 bytes of memory past the heap allocation. An issue was discovered in p11-kit 0.23.6 through 0.23.21. A heap-based buffer overflow has been discovered in the RPC protocol used by p11-kit server/remote commands and the client library. When the remote entity supplies a serialized byte array in a CK_ATTRIBUTE, the receiving entity may not allocate sufficient length for the buffer to store the deserialized value

Platform:
Amazon Linux 2
Product:
p11-kit
Reference:
ALAS2-2021-1601
CVE-2020-29361
CVE-2020-29362
CVE-2020-29363
CVE    3
CVE-2020-29361
CVE-2020-29363
CVE-2020-29362

© SecPod Technologies