CVE-2020-28407 Information
Nov 05, 2023
cve
Description
In swtpm before 0.4.2 and 0.5.x before 0.5.1 a local attacker may be able to overwrite arbitrary files via a symlink attack against a temporary file such as TMP2-00.permall.
Reference
https://bugzilla.suse.com/show_bug.cgi?id=1198395 https://github.com/stefanberger/swtpm/releases/tag/v0.4.2 https://github.com/stefanberger/swtpm/releases/tag/v0.5.1
Share on: