Vulnerability Details CVE-2020-29362
An issue was discovered in p11-kit 0.21.1 through 0.23.21. A heap-based buffer over-read has been discovered in the RPC protocol used by thep11-kit server/remote commands and the client library. When the remote entity supplies a byte array through a serialized PKCS#11 function call, the receiving entity may allow the reading of up to 4 bytes of memory past the heap allocation.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 22.2%
CVSS Severity
CVSS v3 Score 5.3
CVSS v2 Score 5.0
Products affected by CVE-2020-29362
-
cpe:2.3:a:p11-kit_project:p11-kit:0.23.10
-
cpe:2.3:a:p11-kit_project:p11-kit:0.23.11
-
cpe:2.3:a:p11-kit_project:p11-kit:0.23.12
-
cpe:2.3:a:p11-kit_project:p11-kit:0.23.13
-
cpe:2.3:a:p11-kit_project:p11-kit:0.23.14
-
cpe:2.3:a:p11-kit_project:p11-kit:0.23.15
-
cpe:2.3:a:p11-kit_project:p11-kit:0.23.16
-
cpe:2.3:a:p11-kit_project:p11-kit:0.23.16.1
-
cpe:2.3:a:p11-kit_project:p11-kit:0.23.17
-
cpe:2.3:a:p11-kit_project:p11-kit:0.23.18
-
cpe:2.3:a:p11-kit_project:p11-kit:0.23.18.1
-
cpe:2.3:a:p11-kit_project:p11-kit:0.23.19
-
cpe:2.3:a:p11-kit_project:p11-kit:0.23.20
-
cpe:2.3:a:p11-kit_project:p11-kit:0.23.21
-
cpe:2.3:a:p11-kit_project:p11-kit:0.23.6
-
cpe:2.3:a:p11-kit_project:p11-kit:0.23.7
-
cpe:2.3:a:p11-kit_project:p11-kit:0.23.8
-
cpe:2.3:a:p11-kit_project:p11-kit:0.23.9