Yubico libu2f-host 1.1.6

CPE Details

Yubico libu2f-host 1.1.6
1.1.6
2019-11-05
16h25 +00:00
2019-11-05
16h25 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:yubico:libu2f-host:1.1.6:*:*:*:*:*:*:*

Informations

Vendor

yubico

Product

libu2f-host

Version

1.1.6

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2018-20340 2019-03-17 19h06 +00:00 Yubico libu2f-host 1.1.6 contains unchecked buffers in devs.c, which could enable a malicious token to exploit a buffer overflow. An attacker could use this to attempt to execute malicious code using a crafted USB device masquerading as a security token on a computer where the affected library is currently in use. It is not possible to perform this attack with a genuine YubiKey.
6.8
Medium
CVE-2019-9578 2019-03-05 22h00 +00:00 In devs.c in Yubico libu2f-host before 1.1.8, the response to init is misparsed, leaking uninitialized stack memory back to the device.
7.5
High