High severity7.1NVD Advisory· Published Nov 3, 2023· Updated Jun 17, 2026
CVE-2020-28407
CVE-2020-28407
Description
In swtpm before 0.4.2 and 0.5.x before 0.5.1, a local attacker may be able to overwrite arbitrary files via a symlink attack against a temporary file such as TMP2-00.permall.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5- swtpm/swtpmdescription
cpe:2.3:a:swtpm_project:swtpm:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:swtpm_project:swtpm:*:*:*:*:*:*:*:*range: <0.4.2
- cpe:2.3:a:swtpm_project:swtpm:0.5.0:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
3- bugzilla.suse.com/show_bug.cginvdIssue TrackingPatchThird Party Advisory
- github.com/stefanberger/swtpm/releases/tag/v0.4.2nvdRelease Notes
- github.com/stefanberger/swtpm/releases/tag/v0.5.1nvdRelease Notes
News mentions
0No linked articles in our index yet.