7.5
CVSSv3

CVE-2020-29361

Published: 16/12/2020 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

An issue exists in p11-kit 0.21.1 up to and including 0.23.21. Multiple integer overflows have been discovered in the array allocations in the p11-kit library and the p11-kit list command, where overflow checks are missing before calling realloc or calloc.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

p11-kit project p11-kit

debian debian linux 9.0

debian debian linux 10.0

Vendor Advisories

David Cook reported several memory safety issues affecting the RPC protocol in p11-kit, a library providing a way to load and enumerate PKCS#11 modules For the stable distribution (buster), these problems have been fixed in version 02315-2+deb10u1 We recommend that you upgrade your p11-kit packages For the detailed security status of p11-kit p ...
Synopsis Moderate: Migration Toolkit for Containers (MTC) 173 security and bug fix update Type/Severity Security Advisory: Moderate Topic The Migration Toolkit for Containers (MTC) 173 is now availableRed Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring System (CVSS) base ...
Synopsis Moderate: OpenShift Container Platform 4103 security update Type/Severity Security Advisory: Moderate Topic Red Hat OpenShift Container Platform release 4103 is now available withupdates to packages and images that fix several bugs and add enhancementsRed Hat Product Security has rated this update as having a security impact of ...
Synopsis Important: Service Telemetry Framework 14 security update Type/Severity Security Advisory: Important Topic An update is now available for Service Telemetry Framework 14 for RHEL 8Red Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System (CVSS) base score, which g ...
An issue was discovered in p11-kit 0211 through 02321 Multiple integer overflows have been discovered in the array allocations in the p11-kit library and the p11-kit list command, where overflow checks are missing before calling realloc or calloc (CVE-2020-29361) An issue was discovered in p11-kit 0211 through 02321 A heap-based buffer o ...
Multiple integer overflows have been discovered in the array allocations in the p11-kit library and the p11-kit list command in versions 0211 up to 02321, where overflow checks are missing before calling realloc or calloc ...