CVE-2020-11684
14.09.2020, 14:15
AT91bootstrap before 3.9.2 does not properly wipe encryption and authentication keys from memory before passing control to a less privileged software component. This can be exploited to disclose these keys and subsequently encrypt and sign the next boot stage (such as the bootloader).Enginsight
Vendor | Product | Version |
---|---|---|
linux4sam | at91bootstrap | 3.7.2 ≤ 𝑥 < 3.9.2 |
𝑥
= Vulnerable software versions
References