CVE-2020-29362
published 2020-12-16CVE-2020-29362: An issue was discovered in p11-kit 0.21.1 through 0.23.21. A heap-based buffer over-read has been discovered in the RPC protocol used by thep11-kit…
PriorityP430medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
EPSS
2.26%
81.3th percentile
An issue was discovered in p11-kit 0.21.1 through 0.23.21. A heap-based buffer over-read has been discovered in the RPC protocol used by thep11-kit server/remote commands and the client library. When the remote entity supplies a byte array through a serialized PKCS#11 function call, the receiving entity may allow the reading of up to 4 bytes of memory past the heap allocation.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | p11-kit | < p11-kit 0.23.22-1 (bookworm) | p11-kit 0.23.22-1 (bookworm) |
| msrc | cm1_p11-kit_0.23.22-1_on_cbl_mariner_1.0 | — | — |
| p11-kit_project | p11-kit | >= 0 < 0.23.22-1 | 0.23.22-1 |
| p11-kit_project | p11-kit | >= 0 < 0.23.22-1 | 0.23.22-1 |
| p11-kit_project | p11-kit | >= 0 < 0.23.22-1 | 0.23.22-1 |
| p11-kit_project | p11-kit | >= 0 < 0.23.22-1 | 0.23.22-1 |
| p11-kit_project | p11-kit | >= 0.23.6 < 0.23.22 | 0.23.22 |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv5.3MEDIUM
vendor_debian5.3MEDIUM
vendor_msrc5.3MEDIUM
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
cisa_ics·2023-12-14
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
ICS Advisory
##
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
Release DateDecember 14, 2023
Alert CodeICSA-23-348-10
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
- Vulnerabilities: Improper Restriction of XML External Entity Reference, Time-of-check Time-of-use (TOCTOU) Race Condition, Command Injection, Miss
Ubuntu
p11-kit vulnerabilities
vendor_ubuntu·2021-01-05
CVE-2020-29362 p11-kit vulnerabilities
Title: p11-kit vulnerabilities
Summary: Several security issues were fixed in p11-kit.
David Cook discovered that p11-kit incorrectly handled certain memory
operations. An attacker could use this issue to cause p11-kit to crash,
resulting in a denial of service, or possibly execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
p11-kit: out-of-bounds read in p11_rpc_buffer_get_byte_array function in rpc-message.c
vendor_redhat·2020-12-12·CVSS 5.3
CVE-2020-29362 [MEDIUM] CWE-125 p11-kit: out-of-bounds read in p11_rpc_buffer_get_byte_array function in rpc-message.c
p11-kit: out-of-bounds read in p11_rpc_buffer_get_byte_array function in rpc-message.c
An issue was discovered in p11-kit 0.21.1 through 0.23.21. A heap-based buffer over-read has been discovered in the RPC protocol used by thep11-kit server/remote commands and the client library. When the remote entity supplies a byte array through a serialized PKCS#11 function call, the receiving entity may allow the reading of up to 4 bytes of memory past the heap allocation.
Statement: The p11-kit library is primarily intended to be used locally, in which case the attacker needs to have sufficient permission to access the p11-kit communication. Although there may be use cases of p11-kit being used with a remote entity, all parties must be considered trusted.
As a result, Red Hat considers this vulner
Microsoft
An issue was discovered in p11-kit 0.21.1 through 0.23.21. A heap-based buffer over-read has been discovered in the RPC protocol used by thep11-kit server/remote commands and the client library. When
vendor_msrc·2020-12-08·CVSS 5.3
CVE-2020-29362 [MEDIUM] CWE-125 An issue was discovered in p11-kit 0.21.1 through 0.23.21. A heap-based buffer over-read has been discovered in the RPC protocol used by thep11-kit server/remote commands and the client library. When
An issue was discovered in p11-kit 0.21.1 through 0.23.21. A heap-based buffer over-read has been discovered in the RPC protocol used by thep11-kit server/remote commands and the client library. When the remote entity supplies a byte array through a serialized PKCS#11 function call the receiving entity may allow the reading of up to 4 bytes of memory past the heap allocation.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency i
Debian
CVE-2020-29362: p11-kit - An issue was discovered in p11-kit 0.21.1 through 0.23.21. A heap-based buffer o...
vendor_debian·2020·CVSS 5.3
CVE-2020-29362 [MEDIUM] CVE-2020-29362: p11-kit - An issue was discovered in p11-kit 0.21.1 through 0.23.21. A heap-based buffer o...
An issue was discovered in p11-kit 0.21.1 through 0.23.21. A heap-based buffer over-read has been discovered in the RPC protocol used by thep11-kit server/remote commands and the client library. When the remote entity supplies a byte array through a serialized PKCS#11 function call, the receiving entity may allow the reading of up to 4 bytes of memory past the heap allocation.
Scope: local
bookworm: resolved (fixed in 0.23.22-1)
bullseye: resolved (fixed in 0.23.22-1)
forky: resolved (fixed in 0.23.22-1)
sid: resolved (fixed in 0.23.22-1)
trixie: resolved (fixed in 0.23.22-1)
OSV
CVE-2020-29362: An issue was discovered in p11-kit 0
osv·2020-12-16·CVSS 5.3
CVE-2020-29362 [MEDIUM] CVE-2020-29362: An issue was discovered in p11-kit 0
An issue was discovered in p11-kit 0.21.1 through 0.23.21. A heap-based buffer over-read has been discovered in the RPC protocol used by thep11-kit server/remote commands and the client library. When the remote entity supplies a byte array through a serialized PKCS#11 function call, the receiving entity may allow the reading of up to 4 bytes of memory past the heap allocation.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/p11-glue/p11-kit/releaseshttps://github.com/p11-glue/p11-kit/security/advisories/GHSA-5wpq-43j2-6qwchttps://lists.debian.org/debian-lts-announce/2021/01/msg00002.htmlhttps://www.debian.org/security/2021/dsa-4822https://github.com/p11-glue/p11-kit/releaseshttps://github.com/p11-glue/p11-kit/security/advisories/GHSA-5wpq-43j2-6qwchttps://lists.debian.org/debian-lts-announce/2021/01/msg00002.htmlhttps://www.debian.org/security/2021/dsa-4822
2020-12-16
Published