Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2022-23951: Keylime: Quote responses subject to Zip bomb attacks

In Keylime before 6.3.0, quote responses from the agent can contain possibly untrusted ZIP data which can lead to zip bombs.

CVE

Impact

Quote responses from the agent can contain possibly untrusted ZIP data which can lead to zip bombs.

Patches

Users should upgrade to at least 6.3.x.

Workarounds

None

Credit

Many thanks to Matthias Gerstner for finding this issue and for Thore Sommer for the fix.

For more information

If you have any questions or comments about this advisory:

Related news

CVE-2022-23952: Multiple Security Issues (including remote code execution in the Agent component)

In Keylime before 6.3.0, current keylime installer installs the keylime.conf file, which can contain sensitive data, as world-readable.

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907