First published: Wed Dec 16 2020(Updated: )
An issue was discovered in p11-kit 0.21.1 through 0.23.21. Multiple integer overflows have been discovered in the array allocations in the p11-kit library and the p11-kit list command, where overflow checks are missing before calling realloc or calloc.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/p11-kit | 0.23.15-2+deb10u1 0.23.22-1 0.24.1-2 0.25.0-5 | |
IBM Cloud Pak for Security (CP4S) | >=0.21.1<=0.23.21 | |
Debian Debian Linux | =9.0 | |
Debian Debian Linux | =10.0 | |
IBM Cloud Pak for Security (CP4S) | <=1.7.2.0 | |
IBM Cloud Pak for Security (CP4S) | <=1.7.1.0 | |
IBM Cloud Pak for Security (CP4S) | <=1.7.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-29361 is a vulnerability in p11-kit versions 0.21.1 through 0.23.21 that allows for denial of service through multiple integer overflows when allocating memory.
CVE-2020-29361 has a severity rating of 7.5, which is considered high.
p11-kit versions 0.21.1 through 0.23.21 are affected by CVE-2020-29361.
An attacker can exploit CVE-2020-29361 by sending a specially-crafted request using realloc or calloc function.
Yes, there are fixes available for CVE-2020-29361 in versions 0.23.15-2+deb10u1, 0.23.22-1, 0.24.1-2, and 0.25.0-5 of p11-kit.