CVE-2021-37847
02.08.2021, 20:15
crypto/digest.c in Pengutronix barebox through 2021.07.0 leaks timing information because memcmp is used during digest verification.Enginsight
Vendor | Product | Version |
---|---|---|
pengutronix | barebox | 𝑥 ≤ 2021.07.0 |
𝑥
= Vulnerable software versions
References