In devs.c in Yubico libu2f-host before 1.1.8, the response to init is misparsed, leaking uninitialized stack memory back to the device.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade libu2f-host | Jul 30, 2024 | Mar 5, 2019 |
| Gentoo Linux | — | Upgrade app-crypt/libu2f-host. | May 1, 2020 | Mar 5, 2019 |
| Suse | — | Upgrade pam_u2fUpgrade u2f-hostUpgrade libu2f-host-docUpgrade libu2f-host-develUpgrade libu2f-host0 | Jul 5, 2019 | Mar 5, 2019 |
| Ubuntu | — | Upgrade libu2f-host | Nov 19, 2024 | Mar 5, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub