CVE

CVE-2024-29040

Severidad:
MEDIA
Type:
CWE-502 Deserialización de datos no confiables
Fecha de publicación:
28/06/2024
Última modificación:
28/06/2024

Descripción

*** Pendiente de traducción *** This repository hosts source code implementing the Trusted Computing Group&amp;#39;s (TCG) TPM2 Software Stack (TSS). The JSON Quote Info returned by Fapi_Quote has to be deserialized by Fapi_VerifyQuote to the TPM Structure `TPMS_ATTEST`. For the field `TPM2_GENERATED magic` of this structure any number can be used in the JSON structure. The verifier can receive a state which does not represent the actual, possibly malicious state of the device under test. The malicious device might get access to data it shouldn&amp;#39;t, or can use services it shouldn&amp;#39;t be able to. This <br /> issue has been patched in version 4.1.0.