Vulnerability Details CVE-2020-29361
An issue was discovered in p11-kit 0.21.1 through 0.23.21. Multiple integer overflows have been discovered in the array allocations in the p11-kit library and the p11-kit list command, where overflow checks are missing before calling realloc or calloc.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 39.7%
CVSS Severity
CVSS v3 Score 7.5
CVSS v2 Score 5.0
Products affected by CVE-2020-29361
-
cpe:2.3:a:p11-kit_project:p11-kit:0.21.1
-
cpe:2.3:a:p11-kit_project:p11-kit:0.21.2
-
cpe:2.3:a:p11-kit_project:p11-kit:0.21.3
-
cpe:2.3:a:p11-kit_project:p11-kit:0.22.0
-
cpe:2.3:a:p11-kit_project:p11-kit:0.22.1
-
cpe:2.3:a:p11-kit_project:p11-kit:0.23.1
-
cpe:2.3:a:p11-kit_project:p11-kit:0.23.10
-
cpe:2.3:a:p11-kit_project:p11-kit:0.23.11
-
cpe:2.3:a:p11-kit_project:p11-kit:0.23.12
-
cpe:2.3:a:p11-kit_project:p11-kit:0.23.13
-
cpe:2.3:a:p11-kit_project:p11-kit:0.23.14
-
cpe:2.3:a:p11-kit_project:p11-kit:0.23.15
-
cpe:2.3:a:p11-kit_project:p11-kit:0.23.16
-
cpe:2.3:a:p11-kit_project:p11-kit:0.23.16.1
-
cpe:2.3:a:p11-kit_project:p11-kit:0.23.17
-
cpe:2.3:a:p11-kit_project:p11-kit:0.23.18
-
cpe:2.3:a:p11-kit_project:p11-kit:0.23.18.1
-
cpe:2.3:a:p11-kit_project:p11-kit:0.23.19
-
cpe:2.3:a:p11-kit_project:p11-kit:0.23.2
-
cpe:2.3:a:p11-kit_project:p11-kit:0.23.20
-
cpe:2.3:a:p11-kit_project:p11-kit:0.23.21
-
cpe:2.3:a:p11-kit_project:p11-kit:0.23.3
-
cpe:2.3:a:p11-kit_project:p11-kit:0.23.4
-
cpe:2.3:a:p11-kit_project:p11-kit:0.23.5
-
cpe:2.3:a:p11-kit_project:p11-kit:0.23.6
-
cpe:2.3:a:p11-kit_project:p11-kit:0.23.7
-
cpe:2.3:a:p11-kit_project:p11-kit:0.23.8
-
cpe:2.3:a:p11-kit_project:p11-kit:0.23.9
-
cpe:2.3:o:debian:debian_linux:10.0
-
cpe:2.3:o:debian:debian_linux:9.0