Logo
vulnerabilityCVE-2023-33836
Name
CVE-2023-33836
Source
NVD ( link)Debian ( link)
Description
IBM Security Verify Governance 10.0 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 256016.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
renderdoc
Patched

Vulnerability Ratings#


5.3
CVSSv31
9.8
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
yocto
master
1.38
Not Affected
yocto
scarthgap
1.27
Not Affected

Resolved with patches#


renderdoc (yocto:kirkstone)

#
Title
Author
Resolve
1
Sanitise strings printed when received from target
baldurk <baldurk@baldurk.org>
CVE-2023-33836
CVE-2023-33864
CVE-2023-33865
2
Don't call ReadLargeBuffer for socket reads
baldurk <baldurk@baldurk.org>
CVE-2023-33836
CVE-2023-33864
CVE-2023-33865
3
Don't open symlinks when opening logfile
baldurk <baldurk@baldurk.org>
CVE-2023-33836
CVE-2023-33864
CVE-2023-33865
4
Fix incorrect return type
baldurk <baldurk@baldurk.org>
CVE-2023-33836
CVE-2023-33864
CVE-2023-33865