MGASA-2024-0171

Source
https://advisories.mageia.org/MGASA-2024-0171.html
Import Source
https://advisories.mageia.org/MGASA-2024-0171.json
JSON Data
https://api.test.osv.dev/v1/vulns/MGASA-2024-0171
Related
Published
2024-05-09T02:40:29Z
Modified
2024-05-09T02:14:59Z
Summary
Updated tpm2-tss packages fix security vulnerabilities
Details

A flaw was found in the tpm2-tss package, where there was no check that the magic number in the attest is equal to the TPM2GENERATEDVALUE. This flaw allows an attacker to generate arbitrary quote data, which may not be detected by Fapi_VerifyQuote.

References
Credits

Affected packages

Mageia:9 / tpm2-tss

Package

Name
tpm2-tss
Purl
pkg:rpm/mageia/tpm2-tss?distro=mageia-9

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.0.2-1.mga9

Ecosystem specific

{
    "section": "core"
}