CVE-2020-29363

An issue was discovered in p11-kit 0.23.6 through 0.23.21. A heap-based buffer overflow has been discovered in the RPC protocol used by p11-kit server/remote commands and the client library. When the remote entity supplies a serialized byte array in a CK_ATTRIBUTE, the receiving entity may not allocate sufficient length for the buffer to store the deserialized value.
Configurations

Configuration 1

cpe:2.3:a:p11-kit_project:p11-kit:*:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:communications_cloud_native_core_policy:1.14.0:*:*:*:*:*:*:*

Information

Published : 2020-12-16 02:15

Updated : 2022-05-12 02:47


NVD link : CVE-2020-29363

Mitre link : CVE-2020-29363

Products Affected
No products.
CWE