Lucene search

K
ubuntucveUbuntu.comUB:CVE-2023-1018
HistoryFeb 28, 2023 - 12:00 a.m.

CVE-2023-1018

2023-02-2800:00:00
ubuntu.com
ubuntu.com
62
tpm2.0
cryptparameterdecryption
vulnerability
sensitive data
ubuntu
libtpms

5.5 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

0.001 Low

EPSS

Percentile

20.1%

An out-of-bounds read vulnerability exists in TPM2.0’s Module Library
allowing a 2-byte read past the end of a TPM2.0 command in the
CryptParameterDecryption routine. An attacker who can successfully exploit
this vulnerability can read or access sensitive data stored in the TPM.

Bugs

Notes

Author Note
mdeslaur This is VU#782720
OSVersionArchitecturePackageVersionFilename
ubuntu22.04noarchlibtpms<Β 0.9.3-0ubuntu1.22.04.1UNKNOWN
ubuntu22.10noarchlibtpms<Β 0.9.3-0ubuntu1.22.10.1UNKNOWN

5.5 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

0.001 Low

EPSS

Percentile

20.1%