CVE-2020-28407

Severity CVSS v4.0:
Pending analysis
Type:
CWE-59 Link Following
Publication date:
03/11/2023
Last modified:
09/11/2023

Description

In swtpm before 0.4.2 and 0.5.x before 0.5.1, a local attacker may be able to overwrite arbitrary files via a symlink attack against a temporary file such as TMP2-00.permall.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:swtpm_project:swtpm:*:*:*:*:*:*:*:* 0.4.2 (excluding)
cpe:2.3:a:swtpm_project:swtpm:0.5.0:*:*:*:*:*:*:*