SUSE-SU-2019:1123-1
Dashboard / Vulnerabilities / SUSE-SU-2019:1123-1
SUSE-SU-2019:1123-1
Summary: Security update for yubico-piv-tool
Details: This update for yubico-piv-tool fixes the following issues: Security issues fixed: - Fixed an buffer overflow and an out of bounds memory read in ykpiv_transfer_data(), which could be triggered by a malicious token. (CVE-2018-14779, bsc#1104809, YSA-2018-03) - Fixed an buffer overflow and an out of bounds memory read in _ykpiv_fetch_object(), which could be triggered by a malicious token. (CVE-2018-14780, bsc#1104811, YSA-2018-03)
References: https://www.suse.com/support/update/announcement/2019/suse-su-20191123-1/, https://bugzilla.suse.com/1104809, https://bugzilla.suse.com/1104811, https://www.suse.com/security/cve/CVE-2018-14779, https://www.suse.com/security/cve/CVE-2018-14780
Affected packages
Package
Name: yubico-piv-tool
Purl: pkg:rpm/suse/yubico-piv-tool&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015
Affected ranges
Type: ECOSYSTEM
Events:
