I just released swtpm v0.4.2 and v0.5.1. It contains the following fixes:
version 0.4.2:
- swtpm & swtpm_setup:
- Addressed potential symlink attack issue (CVE-2020-28407)
version 0.5.1:
- swtpm & swtpm_setup:
- Addressed potential symlink attack issue (CVE-2020-28407)
- build-sys:
- Fix configure python cryptography error message
Here's the reference to the CVE that should become available some day:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-28407
Errare humanum est. :-)
Cheers!
Stefan