CVE-2020-29361
published 2020-12-16CVE-2020-29361: An issue was discovered in p11-kit 0.21.1 through 0.23.21. Multiple integer overflows have been discovered in the array allocations in the p11-kit library and…
PriorityP340high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
3.35%
87.5th percentile
An issue was discovered in p11-kit 0.21.1 through 0.23.21. Multiple integer overflows have been discovered in the array allocations in the p11-kit library and the p11-kit list command, where overflow checks are missing before calling realloc or calloc.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | p11-kit | < p11-kit 0.23.22-1 (bookworm) | p11-kit 0.23.22-1 (bookworm) |
| msrc | cm1_p11-kit_0.23.22-1_on_cbl_mariner_1.0 | — | — |
| p11-kit_project | p11-kit | >= 0 < 0.23.22-1 | 0.23.22-1 |
| p11-kit_project | p11-kit | >= 0 < 0.23.22-1 | 0.23.22-1 |
| p11-kit_project | p11-kit | >= 0 < 0.23.22-1 | 0.23.22-1 |
| p11-kit_project | p11-kit | >= 0 < 0.23.22-1 | 0.23.22-1 |
| p11-kit_project | p11-kit | 0.21.1 – 0.23.21 | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_msrc7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
cisa_ics·2023-12-14
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
ICS Advisory
##
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
Release DateDecember 14, 2023
Alert CodeICSA-23-348-10
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
- Vulnerabilities: Improper Restriction of XML External Entity Reference, Time-of-check Time-of-use (TOCTOU) Race Condition, Command Injection, Miss
Ubuntu
p11-kit vulnerability
vendor_ubuntu·2021-01-06
CVE-2020-29361 p11-kit vulnerability
Title: p11-kit vulnerability
Summary: Several security issues were fixed in p11-kit.
USN-4677-1 fixed a vulnerability in p11-kit. This update provides
the corresponding update for Ubuntu 14.04 ESM.
Original advisory details:
David Cook discovered that p11-kit incorrectly handled certain memory
operations. An attacker could use this issue to cause p11-kit to crash,
resulting in a denial of service, or possibly execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
p11-kit vulnerabilities
vendor_ubuntu·2021-01-05
CVE-2020-29362 p11-kit vulnerabilities
Title: p11-kit vulnerabilities
Summary: Several security issues were fixed in p11-kit.
David Cook discovered that p11-kit incorrectly handled certain memory
operations. An attacker could use this issue to cause p11-kit to crash,
resulting in a denial of service, or possibly execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
p11-kit: integer overflow when allocating memory for arrays or attributes and object identifiers
vendor_redhat·2020-12-12·CVSS 7.5
CVE-2020-29361 [HIGH] CWE-190 p11-kit: integer overflow when allocating memory for arrays or attributes and object identifiers
p11-kit: integer overflow when allocating memory for arrays or attributes and object identifiers
An issue was discovered in p11-kit 0.21.1 through 0.23.21. Multiple integer overflows have been discovered in the array allocations in the p11-kit library and the p11-kit list command, where overflow checks are missing before calling realloc or calloc.
Statement: The p11-kit library is primarily intended to be used locally, in which case the attacker needs to have sufficient permission to access the p11-kit communication. Although there may be use cases of p11-kit being used with a remote entity, all parties must be considered trusted.
As a result, Red Hat considers this vulnerability with a Medium severity.
Package: p11-kit (Red Hat Enterprise Linux 6) - Not affected
Package: p11-kit (Red
Microsoft
An issue was discovered in p11-kit 0.21.1 through 0.23.21. Multiple integer overflows have been discovered in the array allocations in the p11-kit library and the p11-kit list command where overflow c
vendor_msrc·2020-12-08·CVSS 7.5
CVE-2020-29361 [HIGH] CWE-190 An issue was discovered in p11-kit 0.21.1 through 0.23.21. Multiple integer overflows have been discovered in the array allocations in the p11-kit library and the p11-kit list command where overflow c
An issue was discovered in p11-kit 0.21.1 through 0.23.21. Multiple integer overflows have been discovered in the array allocations in the p11-kit library and the p11-kit list command where overflow checks are missing before calling realloc or calloc.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to ad
Debian
CVE-2020-29361: p11-kit - An issue was discovered in p11-kit 0.21.1 through 0.23.21. Multiple integer over...
vendor_debian·2020·CVSS 7.5
CVE-2020-29361 [HIGH] CVE-2020-29361: p11-kit - An issue was discovered in p11-kit 0.21.1 through 0.23.21. Multiple integer over...
An issue was discovered in p11-kit 0.21.1 through 0.23.21. Multiple integer overflows have been discovered in the array allocations in the p11-kit library and the p11-kit list command, where overflow checks are missing before calling realloc or calloc.
Scope: local
bookworm: resolved (fixed in 0.23.22-1)
bullseye: resolved (fixed in 0.23.22-1)
forky: resolved (fixed in 0.23.22-1)
sid: resolved (fixed in 0.23.22-1)
trixie: resolved (fixed in 0.23.22-1)
OSV
CVE-2020-29361: An issue was discovered in p11-kit 0
osv·2020-12-16·CVSS 7.5
CVE-2020-29361 [HIGH] CVE-2020-29361: An issue was discovered in p11-kit 0
An issue was discovered in p11-kit 0.21.1 through 0.23.21. Multiple integer overflows have been discovered in the array allocations in the p11-kit library and the p11-kit list command, where overflow checks are missing before calling realloc or calloc.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/p11-glue/p11-kit/releaseshttps://github.com/p11-glue/p11-kit/security/advisories/GHSA-q4r3-hm6m-mvc2https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3Ehttps://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2021/01/msg00002.htmlhttps://www.debian.org/security/2021/dsa-4822https://github.com/p11-glue/p11-kit/releaseshttps://github.com/p11-glue/p11-kit/security/advisories/GHSA-q4r3-hm6m-mvc2https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3Ehttps://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2021/01/msg00002.htmlhttps://www.debian.org/security/2021/dsa-4822
2020-12-16
Published