Revisions of tpm2.0-tools
Marcus Rueckert (darix)
committed
(revision 2)
- Add 0001-tpm2_checkquote-Fix-check-of-magic-number.patch: tpm2_checkquote did not check whether the magic number in the attest is equal to TPM2_GENERATED_VALUE, which might allow a malicious actor to generate arbitrary quote data, undetected by tpm2_checkquote (bsc#1223687, CVE-2024-29038). - Add 0001-tpm2_checkquote-Add-comparison-of-pcr-selection.patch: tpm2_checkquote did not compare the --pcr parameter passed to the tool with the attest. A malicious actor might thus be able to fake a valid attestation (bsc#1223689, CVE-2024-29039).
Ruediger Oertel (oertel)
committed
(revision 1)
initialize package
Displaying all 2 revisions