Improper Verification of Cryptographic Signature Affecting fwupd package, versions <1.2.13-1


Severity

Recommended
0.0
medium
0
10

Snyk's Security Team recommends NVD's CVSS assessment. Learn more

Threat Intelligence

EPSS
0.49% (39th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-DEBIAN10-FWUPD-571639
  • published7 Jun 2020
  • disclosed15 Sept 2020

Introduced: 7 Jun 2020

CVE-2020-10759  (opens in a new tab)
CWE-347  (opens in a new tab)

How to fix?

Upgrade Debian:10 fwupd to version 1.2.13-1 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream fwupd package and not the fwupd package as distributed by Debian. See How to fix? for Debian:10 relevant fixed versions and status.

A PGP signature bypass flaw was found in fwupd (all versions), which could lead to the installation of unsigned firmware. As per upstream, a signature bypass is theoretically possible, but not practical because the Linux Vendor Firmware Service (LVFS) is either not implemented or enabled in versions of fwupd shipped with Red Hat Enterprise Linux 7 and 8. The highest threat from this vulnerability is to confidentiality and integrity.

CVSS Base Scores

version 3.1