CVE-2020-29361: An issue was discovered in p11-kit 0.21.1 through 0.23.21. Multiple integer overflows have been discovered in the array allocations in the p11-kit library and the p11-kit list command where overflow checks are missing before calling realloc or calloc.

Overview

Severity
High (CVSS 7.5)
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploit Status
Not Exploited
Patch Tuesday
2020-Dec
Released
2020-12-18
EPSS Score
0.24% (percentile: 47.9%)

Affected Products (1)

Mariner

  • cm1 p11-kit 0.23.22-1 on CBL Mariner 1.0

Revision History

  • 2020-12-18: Information published.