RSS   Vulnerabilities for 'Tough'   RSS

2021-10-19
 
CVE-2021-41150

CWE-22
 

 
Tough provides a set of Rust libraries and tools for using and generating the update framework (TUF) repositories. The tough library, prior to 0.12.0, does not properly sanitize delegated role names when caching a repository, or when loading a repository from the filesystem. When the repository is cached or loaded, files ending with the .json extension could be overwritten with role metadata anywhere on the system. A fix is available in version 0.12.0. No workarounds to this issue are known.

 
 
CVE-2021-41149

CWE-22
 

 
Tough provides a set of Rust libraries and tools for using and generating the update framework (TUF) repositories. The tough library, prior to 0.12.0, does not properly sanitize target names when caching a repository, or when saving specific targets to an output directory. When targets are cached or saved, files could be overwritten with arbitrary content anywhere on the system. A fix is available in version 0.12.0. No workarounds to this issue are known.

 
2020-07-09
 
CVE-2020-15093

CWE-347
 

 
The tough library (Rust/crates.io) prior to version 0.7.1 does not properly verify the threshold of cryptographic signatures. It allows an attacker to duplicate a valid signature in order to circumvent TUF requiring a minimum threshold of unique signatures before the metadata is considered valid. A fix is available in version 0.7.1. CVE-2020-6174 is assigned to the same vulnerability in the TUF reference implementation.

 

 >>> Vendor: Amazon 26 Products
Kindle touch
Kindle for pc
Merchant sdk
Elastic load balancing api tools
Flexible payments service
Ec2 api tools java library
Kindle
Fire os
Amazon key firmware
Amazon music
Payfort
Payfort-php-sdk
Amazon web services freertos
Freertos
Amazon web services software development kit
Freertos\+fat
Audible
Firecracker
Aws-lambda
Aws javascript s3 explorer
Tough
Aws s3 crypto sdk
Workspaces
Sockeye
Aws opensearch
Aws client vpn


Copyright 2022, cxsecurity.com

 

Back to Top