CVE-2020-29363
published 2020-12-16CVE-2020-29363: An issue was discovered in p11-kit 0.23.6 through 0.23.21. A heap-based buffer overflow has been discovered in the RPC protocol used by p11-kit server/remote…
PriorityP344high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
3.52%
88.0th percentile
An issue was discovered in p11-kit 0.23.6 through 0.23.21. A heap-based buffer overflow has been discovered in the RPC protocol used by p11-kit server/remote commands and the client library. When the remote entity supplies a serialized byte array in a CK_ATTRIBUTE, the receiving entity may not allocate sufficient length for the buffer to store the deserialized value.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | p11-kit | < p11-kit 0.23.22-1 (bookworm) | p11-kit 0.23.22-1 (bookworm) |
| msrc | cm1_p11-kit_0.23.22-1_on_cbl_mariner_1.0 | — | — |
| oracle | communications_cloud_native_core_policy | — | — |
| p11-kit_project | p11-kit | >= 0 < 0.23.22-1 | 0.23.22-1 |
| p11-kit_project | p11-kit | >= 0 < 0.23.22-1 | 0.23.22-1 |
| p11-kit_project | p11-kit | >= 0 < 0.23.22-1 | 0.23.22-1 |
| p11-kit_project | p11-kit | >= 0 < 0.23.22-1 | 0.23.22-1 |
| p11-kit_project | p11-kit | >= 0.23.6 < 0.23.22 | 0.23.22 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_msrc7.5HIGH
vendor_oracle7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
cisa_ics·2023-12-14
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
ICS Advisory
##
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
Release DateDecember 14, 2023
Alert CodeICSA-23-348-10
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
- Vulnerabilities: Improper Restriction of XML External Entity Reference, Time-of-check Time-of-use (TOCTOU) Race Condition, Command Injection, Miss
Oracle
Oracle Oracle Communications Risk Matrix: Policy (p11-kit) — CVE-2020-29363
vendor_oracle·2022-04-15·CVSS 7.5
CVE-2020-29363 [HIGH] Oracle Oracle Communications Risk Matrix: Policy (p11-kit) — CVE-2020-29363
Oracle Oracle Communications Risk Matrix: Policy (p11-kit) vulnerability
CVE: CVE-2020-29363
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2022 (APR 2022)
Ubuntu
p11-kit vulnerabilities
vendor_ubuntu·2021-01-05
CVE-2020-29362 p11-kit vulnerabilities
Title: p11-kit vulnerabilities
Summary: Several security issues were fixed in p11-kit.
David Cook discovered that p11-kit incorrectly handled certain memory
operations. An attacker could use this issue to cause p11-kit to crash,
resulting in a denial of service, or possibly execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
p11-kit: out-of-bounds write in p11_rpc_buffer_get_byte_array_value function in rpc-message.c
vendor_redhat·2020-12-12·CVSS 7.5
CVE-2020-29363 [HIGH] CWE-787 p11-kit: out-of-bounds write in p11_rpc_buffer_get_byte_array_value function in rpc-message.c
p11-kit: out-of-bounds write in p11_rpc_buffer_get_byte_array_value function in rpc-message.c
An issue was discovered in p11-kit 0.23.6 through 0.23.21. A heap-based buffer overflow has been discovered in the RPC protocol used by p11-kit server/remote commands and the client library. When the remote entity supplies a serialized byte array in a CK_ATTRIBUTE, the receiving entity may not allocate sufficient length for the buffer to store the deserialized value.
Statement: The p11-kit library is primarily intended to be used locally, in which case the attacker needs to have sufficient permission to access the p11-kit communication. Although there may be use cases of p11-kit being used with a remote entity, all parties must be considered trusted.
As a result, Red Hat considers this vulnerabi
Microsoft
An issue was discovered in p11-kit 0.23.6 through 0.23.21. A heap-based buffer overflow has been discovered in the RPC protocol used by p11-kit server/remote commands and the client library. When the
vendor_msrc·2020-12-08·CVSS 7.5
CVE-2020-29363 [HIGH] CWE-787 An issue was discovered in p11-kit 0.23.6 through 0.23.21. A heap-based buffer overflow has been discovered in the RPC protocol used by p11-kit server/remote commands and the client library. When the
An issue was discovered in p11-kit 0.23.6 through 0.23.21. A heap-based buffer overflow has been discovered in the RPC protocol used by p11-kit server/remote commands and the client library. When the remote entity supplies a serialized byte array in a CK_ATTRIBUTE the receiving entity may not allocate sufficient length for the buffer to store the deserialized value.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this wor
Debian
CVE-2020-29363: p11-kit - An issue was discovered in p11-kit 0.23.6 through 0.23.21. A heap-based buffer o...
vendor_debian·2020·CVSS 7.5
CVE-2020-29363 [HIGH] CVE-2020-29363: p11-kit - An issue was discovered in p11-kit 0.23.6 through 0.23.21. A heap-based buffer o...
An issue was discovered in p11-kit 0.23.6 through 0.23.21. A heap-based buffer overflow has been discovered in the RPC protocol used by p11-kit server/remote commands and the client library. When the remote entity supplies a serialized byte array in a CK_ATTRIBUTE, the receiving entity may not allocate sufficient length for the buffer to store the deserialized value.
Scope: local
bookworm: resolved (fixed in 0.23.22-1)
bullseye: resolved (fixed in 0.23.22-1)
forky: resolved (fixed in 0.23.22-1)
sid: resolved (fixed in 0.23.22-1)
trixie: resolved (fixed in 0.23.22-1)
OSV
CVE-2020-29363: An issue was discovered in p11-kit 0
osv·2020-12-16·CVSS 7.5
CVE-2020-29363 [HIGH] CVE-2020-29363: An issue was discovered in p11-kit 0
An issue was discovered in p11-kit 0.23.6 through 0.23.21. A heap-based buffer overflow has been discovered in the RPC protocol used by p11-kit server/remote commands and the client library. When the remote entity supplies a serialized byte array in a CK_ATTRIBUTE, the receiving entity may not allocate sufficient length for the buffer to store the deserialized value.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/p11-glue/p11-kit/releaseshttps://github.com/p11-glue/p11-kit/security/advisories/GHSA-5j67-fw89-fp6xhttps://www.debian.org/security/2021/dsa-4822https://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://github.com/p11-glue/p11-kit/releaseshttps://github.com/p11-glue/p11-kit/security/advisories/GHSA-5j67-fw89-fp6xhttps://www.debian.org/security/2021/dsa-4822https://www.oracle.com/security-alerts/cpuapr2022.html
2020-12-16
Published