VDB

CVE-2020-28407

CVE-2020-28407 REJECTED

In swtpm before 0.4.2 and 0.5.x before 0.5.1, a local attacker may be able to overwrite arbitrary files via a symlink attack against a temporary file such as TMP2-00.permall.

EPSS 0.02% · 3.3th percentile

Risk Scores

EPSS Score
0.02%
3.3th percentile

Affected Products

VendorProductVersions
Ubuntu:22.04:LTSswtpm0, 0.6.1-0ubuntu1, 0.6.1-0ubuntu5

Timeline

  • Nov 3, 2023 CVE Published
  • Nov 3, 2023 EPSS Score
  • Dec 4, 2023 EPSS Score
  • Jan 3, 2024 EPSS Score
  • Feb 3, 2024 EPSS Score
  • Mar 5, 2024 EPSS Score
  • Apr 4, 2024 EPSS Score
  • May 5, 2024 EPSS Score
  • Jun 5, 2024 EPSS Score
  • Jul 5, 2024 EPSS Score
  • Aug 5, 2024 EPSS Score
  • Sep 5, 2024 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›