CVE-2020-29361 - log back

CVE-2020-29361 edited at 12 Dec 2020 15:39:05
References
https://github.com/p11-glue/p11-kit/security/advisories/GHSA-q4r3-hm6m-mvc2
+ https://github.com/p11-glue/p11-kit/commit/5307a1d21a50cacd06f471a873a018d23ba4b963
+ https://github.com/p11-glue/p11-kit/commit/bd670b1d4984b27d6a397b9ddafaf89ab26e4e7f
CVE-2020-29361 edited at 12 Dec 2020 15:31:07
Severity
- Unknown
+ Medium
Remote
- Unknown
+ Local
Type
- Unknown
+ Arbitrary code execution
CVE-2020-29361 edited at 12 Dec 2020 15:28:53
Description
+ Multiple integer overflows have been discovered in the array allocations in the p11-kit library and the p11-kit list command in versions 0.21.1 up to 0.23.21, where overflow checks are missing before calling realloc or calloc.
References
+ https://github.com/p11-glue/p11-kit/security/advisories/GHSA-q4r3-hm6m-mvc2
Notes
CVE-2020-29361 created at 12 Dec 2020 15:27:12