CVE-2020-28045: High severity pax prolinos vulnerability
An unsigned-library issue was discovered in ProlinOS through 2.4.161.8859R. This OS requires installed applications and all system binaries to be signed either by the manufacturer or by the Point Of Sale application developer and distributor. The signature is a 2048-byte RSA signature verified in the kernel prior to ELF execution. Shared libraries, however, do not need to be signed, and they are not verified. An attacker may execute a custom binary by compiling it as a shared object and loading it via LDPRELOAD.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-28045?
CVE-2020-28045 is considered a high-severity vulnerability due to its potential to allow unsigned libraries to be executed.
How do I fix CVE-2020-28045?
To fix CVE-2020-28045, ensure all applications and system binaries are signed properly by the manufacturer or authorized developers.
What software versions are affected by CVE-2020-28045?
CVE-2020-28045 affects ProlinOS versions up to and including 2.4.161.8859R.
What are the risks associated with CVE-2020-28045?
The risks associated with CVE-2020-28045 include unauthorized access and execution of malicious unsigned libraries.
Is there a patch available for CVE-2020-28045?
As of now, there is no specific patch available for CVE-2020-28045; users must ensure proper signing of binaries and applications.