Yubico
yubico
26 CVEs • 54 products
Products (54)
Click to collapseToggle
Products (54)
Click to collapse
CVEs (26)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Yubico pam-u2f 1.0.7 attempts parsing of the configured authfile (default $HOME/.config/Yubico/u2f_keys) as root (unless openasuser was enabled), and does not properly verify that the path lacks symlinks pointing to othe...Show more |
2Debian Yubico2Debian Linux Libu2f HostNov 21, 2024 Mar 21, 2019 N/A· v4 6.8 MEDIUM· v3 4.6 MEDIUM· v2 Yubico libu2f-host 1.1.6 contains unchecked buffers in devs.c, which could enable a malicious token to exploit a buffer overflow. An attacker could use this to attempt to execute malicious code using a crafted USB device...Show more |
In devs.c in Yubico libu2f-host before 1.1.8, the response to init is misparsed, leaking uninitialized stack memory back to the device. |
1Yubico 3Piv Manager Piv ToolSmart Card MinidriverNov 21, 2024 Aug 15, 2018 N/A· v4 4.6 MEDIUM· v3 2.1 LOW· v2 An out-of-bounds read issue was discovered in the Yubico-Piv 1.5.0 smartcard driver. The file lib/ykpiv.c contains the following code in the function `_ykpiv_fetch_object()`: {% highlight c %} if(sw == SW_SUCCESS) { size...Show more |
1Yubico 3Piv Manager Piv ToolSmart Card MinidriverNov 21, 2024 Aug 15, 2018 N/A· v4 6.8 MEDIUM· v3 7.2 HIGH· v2 A buffer overflow issue was discovered in the Yubico-Piv 1.5.0 smartcard driver. The file lib/ykpiv.c contains the following code in the function `ykpiv_transfer_data()`: {% highlight c %} if(*out_len + recv_len - 2 > ma...Show more |
In check_user_token in util.c in the Yubico PAM module (aka pam_yubico) 2.18 through 2.25, successful logins can leak file descriptors to the auth mapping file, which can lead to information disclosure (serial number of...Show more |