Yubico Libu2F-Host vulnerabilities
2 known vulnerabilities affecting yubico/libu2f-host.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2019-9578P3HIGHCVSS 7.5fixed in 1.1.82019-03-05
CVE-2019-9578 [HIGH] CWE-908 CVE-2019-9578: In devs.c in Yubico libu2f-host before 1.1.8, the response to init is misparsed, leaking uninitializ
In devs.c in Yubico libu2f-host before 1.1.8, the response to init is misparsed, leaking uninitialized stack memory back to the device.
nvdosv
CVE-2018-20340P4MEDIUMCVSS 6.8v1.1.62019-03-21
CVE-2018-20340 [MEDIUM] CWE-119 CVE-2018-20340: Yubico libu2f-host 1.1.6 contains unchecked buffers in devs.c, which could enable a malicious token
Yubico libu2f-host 1.1.6 contains unchecked buffers in devs.c, which could enable a malicious token to exploit a buffer overflow. An attacker could use this to attempt to execute malicious code using a crafted USB device masquerading as a security token on a computer where the affected library is currently in use. It is not possible to perform this a
nvdosv