Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Fishilicoo

#48150of 56,330
5.5Total CVSS
Vulnerabilities · 1
PT-2021-20813
5.5
2021-04-19
Libtpms · Libtpms · CVE-2021-3505
Name of the Vulnerable Software and Affected Versions: libtpms versions prior to 0.8.0 Description: A flaw was found in the TPM 2 implementation of libtpms, where it returns 2048 bit keys with approximately 1984 bit strength due to a bug in the TCG specification. The issue lies in the key creation algorithm, specifically in the RsaAdjustPrimeCandidate() function, which is called before the prime number check. This poses a significant threat to data confidentiality. Recommendations: For versions prior to 0.8.0, update to version 0.8.0 or later to resolve the issue.