CVE-2019-9578
05.03.2019, 23:29
In devs.c in Yubico libu2f-host before 1.1.8, the response to init is misparsed, leaking uninitialized stack memory back to the device.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| yubico | libu2f-host | 𝑥 < 1.1.8 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
openSUSE / SLES Releases
openSUSE Product | |||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| libu2f-host-devel |
| ||||||||||||||||||||||||||||||||||||||||||||||||||||
| libu2f-host0 |
| ||||||||||||||||||||||||||||||||||||||||||||||||||||
| pam_u2f |
| ||||||||||||||||||||||||||||||||||||||||||||||||||||
| u2f-host |
|
Common Weakness Enumeration
References