CVE-2018-20340
published 2019-03-21CVE-2018-20340: Yubico libu2f-host 1.1.6 contains unchecked buffers in devs.c, which could enable a malicious token to exploit a buffer overflow. An attacker could use this to…
PriorityP428medium6.8CVSS 3.0
AVPACLPRNUINSUCHIHAH
EPSS
0.50%
40.0th percentile
Yubico libu2f-host 1.1.6 contains unchecked buffers in devs.c, which could enable a malicious token to exploit a buffer overflow. An attacker could use this to attempt to execute malicious code using a crafted USB device masquerading as a security token on a computer where the affected library is currently in use. It is not possible to perform this attack with a genuine YubiKey.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | libu2f-host | < libu2f-host 1.1.7-1 (bookworm) | libu2f-host 1.1.7-1 (bookworm) |
| yubico | libu2f-host | — | — |
| yubico | libu2f-host | >= 0 < 1.1.7-1 | 1.1.7-1 |
| yubico | libu2f-host | >= 0 < 1.1.7-1 | 1.1.7-1 |
| yubico | libu2f-host | >= 0 < 1.1.7-1 | 1.1.7-1 |
| yubico | libu2f-host | >= 0 < 1.1.7-1 | 1.1.7-1 |
CVSS provenance
nvdv3.06.8MEDIUMCVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
vendor_debian6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-rc58-rfcj-mcrr: Yubico libu2f-host 1
ghsa_unreviewed·2022-05-13
CVE-2018-20340 [MEDIUM] CWE-119 GHSA-rc58-rfcj-mcrr: Yubico libu2f-host 1
Yubico libu2f-host 1.1.6 contains unchecked buffers in devs.c, which could enable a malicious token to exploit a buffer overflow. An attacker could use this to attempt to execute malicious code using a crafted USB device masquerading as a security token on a computer where the affected library is currently in use. It is not possible to perform this attack with a genuine YubiKey.
OSV
CVE-2018-20340: Yubico libu2f-host 1
osv·2019-03-21·CVSS 6.8
CVE-2018-20340 [MEDIUM] CVE-2018-20340: Yubico libu2f-host 1
Yubico libu2f-host 1.1.6 contains unchecked buffers in devs.c, which could enable a malicious token to exploit a buffer overflow. An attacker could use this to attempt to execute malicious code using a crafted USB device masquerading as a security token on a computer where the affected library is currently in use. It is not possible to perform this attack with a genuine YubiKey.
Debian
CVE-2018-20340: libu2f-host - Yubico libu2f-host 1.1.6 contains unchecked buffers in devs.c, which could enabl...
vendor_debian·2018·CVSS 6.8
CVE-2018-20340 [MEDIUM] CVE-2018-20340: libu2f-host - Yubico libu2f-host 1.1.6 contains unchecked buffers in devs.c, which could enabl...
Yubico libu2f-host 1.1.6 contains unchecked buffers in devs.c, which could enable a malicious token to exploit a buffer overflow. An attacker could use this to attempt to execute malicious code using a crafted USB device masquerading as a security token on a computer where the affected library is currently in use. It is not possible to perform this attack with a genuine YubiKey.
Scope: local
bookworm: resolved (fixed in 1.1.7-1)
bullseye: resolved (fixed in 1.1.7-1)
forky: resolved (fixed in 1.1.7-1)
sid: resolved (fixed in 1.1.7-1)
trixie: resolved (fixed in 1.1.7-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://blog.inhq.net/posts/yubico-libu2f-host-vuln-part1/https://developers.yubico.com/libu2f-host/Release_Notes.htmlhttps://seclists.org/bugtraq/2019/Feb/23https://security.gentoo.org/glsa/202004-15https://www.debian.org/security/2019/dsa-4389https://www.yubico.com/support/security-advisories/ysa-2019-01/https://blog.inhq.net/posts/yubico-libu2f-host-vuln-part1/https://developers.yubico.com/libu2f-host/Release_Notes.htmlhttps://seclists.org/bugtraq/2019/Feb/23https://security.gentoo.org/glsa/202004-15https://www.debian.org/security/2019/dsa-4389https://www.yubico.com/support/security-advisories/ysa-2019-01/
2019-03-21
Published