openSUSE-SU-2021:0799-1
Dashboard / Vulnerabilities / openSUSE-SU-2021:0799-1
openSUSE-SU-2021:0799-1
Summary: Security update for libu2f-host
Details: This update for libu2f-host fixes the following issues: This update ships the u2f-host package (jsc#ECO-3687 bsc#1184648) Version 1.1.10 (released 2019-05-15) - Add new devices to udev rules. - Fix a potentially uninitialized buffer (CVE-2019-9578, bsc#1128140) Version 1.1.9 (released 2019-03-06) - Fix CID copying from the init response, which broke compatibility with some devices. Version 1.1.8 (released 2019-03-05) - Add udev rules - Drop 70-old-u2f.rules and use 70-u2f.rules for everything - Use a random nonce for setting up CID to prevent fingerprinting - CVE-2019-9578: Parse the response to init in a more stable way to prevent leakage of uninitialized stack memory back to the device (bsc#1128140). Version 1.1.7 (released 2019-01-08) - Fix for trusting length from device in device init. - Fix for buffer overflow when receiving data from device. (YSA-2019-01, CVE-2018-20340, bsc#1124781) - Add udev rules for some new devices. - Add udev rule for Feitian ePass FIDO - Add a timeout to the register and authenticate actions. This update was imported from the SUSE:SLE-15:Update update project.
References: https://lists.opensuse.org/archives/list/[email protected]/thread/QRDOETNQVM5LVLJRZMNGQEBNRFW4ZWEV/, https://bugzilla.suse.com/1124781, https://bugzilla.suse.com/1128140, https://bugzilla.suse.com/1184648, https://www.suse.com/security/cve/CVE-2018-20340, https://www.suse.com/security/cve/CVE-2019-9578
Affected packages
Package
Name: libu2f-host
Purl: pkg:rpm/opensuse/libu2f-host&distro=openSUSE%20Leap%2015.2
Affected ranges
Type: ECOSYSTEM
Events:
