CVE-2024-29038

tpm2-tools is the source repository for the Trusted Platform Module (TPM2.0) tools. A malicious attacker can generate arbitrary quote data which is not detected by `tpm2 checkquote`. This issue was patched in version 5.7.
Configurations

No configuration.

History

21 Nov 2024, 09:07

Type Values Removed Values Added
References () https://github.com/tpm2-software/tpm2-tools/releases/tag/5.7 - () https://github.com/tpm2-software/tpm2-tools/releases/tag/5.7 -
References () https://github.com/tpm2-software/tpm2-tools/security/advisories/GHSA-5495-c38w-gr6f - () https://github.com/tpm2-software/tpm2-tools/security/advisories/GHSA-5495-c38w-gr6f -

01 Jul 2024, 12:37

Type Values Removed Values Added
Summary
  • (es) tpm2-tools es el repositorio de origen de las herramientas del Módulo de plataforma segura (TPM2.0). Un atacante malintencionado puede generar datos de cotizaciones arbitrarios que no son detectados por "tpm2 checkquote". Este problema se solucionó en la versión 5.7.

28 Jun 2024, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-06-28 14:15

Updated : 2024-11-21 09:07


NVD link : CVE-2024-29038

Mitre link : CVE-2024-29038

CVE.ORG link : CVE-2024-29038


JSON object : View

Products Affected

No product.

CWE
CWE-1283

Mutable Attestation or Measurement Reporting Data

CWE-1390

Weak Authentication