Day[0] cover image

[binary] An OpenBSD overflow and TPM bugs

Day[0]

00:00

Is GoLang a Safer Bet?

QuarkSlab put out a blog post on two vulnerabilities in the TPM 2.0 reference implementation, which I saw a bit of information on a few weeks ago but it was just like service level details at that point. So for those who aren't really familiar with what a TPM is, it stands for trusted platform module. And both vulnerabilities are actually in the same function. They're in this crypt parameter decryption routine,. But they don't actually verify that there's data to send back and forth. It'll try to pull an out of bounds read by truncating the packet because it'll try to decrypt these parameters. You can opt to send them into memory even though it

Play episode from 17:36
Transcript

The AI-powered Podcast Player

Save insights by tapping your headphones, chat with episodes, discover the best highlights - and more!
App store bannerPlay store banner
Get the app