openSUSE-SU-2019:1341-1
Dashboard / Vulnerabilities / openSUSE-SU-2019:1341-1
openSUSE-SU-2019:1341-1
Summary: Security update for yubico-piv-tool
Details: This update for yubico-piv-tool fixes the following issues: Security issues fixed: - Fixed an buffer overflow and an out of bounds memory read in ykpiv_transfer_data(), which could be triggered by a malicious token. (CVE-2018-14779, bsc#1104809, YSA-2018-03) - Fixed an buffer overflow and an out of bounds memory read in _ykpiv_fetch_object(), which could be triggered by a malicious token. (CVE-2018-14780, bsc#1104811, YSA-2018-03) This update was imported from the SUSE:SLE-15:Update update project.
References: https://lists.opensuse.org/archives/list/[email protected]/thread/SKNALFJRS7OCVOWZEDZL7DT5WORQDQGM/#SKNALFJRS7OCVOWZEDZL7DT5WORQDQGM, https://bugzilla.suse.com/1104809, https://bugzilla.suse.com/1104811, https://www.suse.com/security/cve/CVE-2018-14779, https://www.suse.com/security/cve/CVE-2018-14780
Affected packages
Package
Name: yubico-piv-tool
Purl: pkg:rpm/opensuse/yubico-piv-tool&distro=openSUSE%20Leap%2015.0
Affected ranges
Type: ECOSYSTEM
Events:
