Shodan
Maps
Images
Monitor
Developer
More...
Dashboard
View Api Docs
Vulnerabilities
By Date
Known Exploited
Advanced Search
Vulnerable Software
Vendors
Products
Vulnerability Details CVE-2019-9578
In devs.c in Yubico libu2f-host before 1.1.8, the response to init is misparsed, leaking uninitialized stack memory back to the device.
Exploit prediction scoring system (EPSS) score
EPSS Score
0.015
EPSS Ranking
80.5%
CVSS Severity
CVSS v3 Score
7.5
CVSS v2 Score
5.0
References
http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00012.html
http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00018.html
https://blog.inhq.net/posts/yubico-libu2f-host-vuln-part2/
https://developers.yubico.com/libu2f-host/Release_Notes.html
https://github.com/Yubico/libu2f-host/commit/e4bb58cc8b6202a421e65f8230217d8ae6e16eb5
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GMA4H6AZFYIR3LA5VKKEJZNCCIVMUCFQ/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/S4YCFMSNMXZ7XC4U6WXPQA7JCXC6VOAJ/
https://security.gentoo.org/glsa/202004-15
http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00012.html
http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00018.html
https://blog.inhq.net/posts/yubico-libu2f-host-vuln-part2/
https://developers.yubico.com/libu2f-host/Release_Notes.html
https://github.com/Yubico/libu2f-host/commit/e4bb58cc8b6202a421e65f8230217d8ae6e16eb5
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GMA4H6AZFYIR3LA5VKKEJZNCCIVMUCFQ/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/S4YCFMSNMXZ7XC4U6WXPQA7JCXC6VOAJ/
https://security.gentoo.org/glsa/202004-15
Products affected by CVE-2019-9578
Yubico
»
Libu2f-Host
»
Version:
0.0
cpe:2.3:a:yubico:libu2f-host:0.0
Yubico
»
Libu2f-Host
»
Version:
0.0.1
cpe:2.3:a:yubico:libu2f-host:0.0.1
Yubico
»
Libu2f-Host
»
Version:
0.0.2
cpe:2.3:a:yubico:libu2f-host:0.0.2
Yubico
»
Libu2f-Host
»
Version:
0.0.3
cpe:2.3:a:yubico:libu2f-host:0.0.3
Yubico
»
Libu2f-Host
»
Version:
0.0.4
cpe:2.3:a:yubico:libu2f-host:0.0.4
Yubico
»
Libu2f-Host
»
Version:
1.0.0
cpe:2.3:a:yubico:libu2f-host:1.0.0
Yubico
»
Libu2f-Host
»
Version:
1.1.0
cpe:2.3:a:yubico:libu2f-host:1.1.0
Yubico
»
Libu2f-Host
»
Version:
1.1.2
cpe:2.3:a:yubico:libu2f-host:1.1.2
Yubico
»
Libu2f-Host
»
Version:
1.1.3
cpe:2.3:a:yubico:libu2f-host:1.1.3
Yubico
»
Libu2f-Host
»
Version:
1.1.4
cpe:2.3:a:yubico:libu2f-host:1.1.4
Yubico
»
Libu2f-Host
»
Version:
1.1.5
cpe:2.3:a:yubico:libu2f-host:1.1.5
Yubico
»
Libu2f-Host
»
Version:
1.1.6
cpe:2.3:a:yubico:libu2f-host:1.1.6
Yubico
»
Libu2f-Host
»
Version:
1.1.7
cpe:2.3:a:yubico:libu2f-host:1.1.7
Products
Monitor
Search Engine
Developer API
Maps
Bulk Data
Images
Snippets
Pricing
Membership
API Subscriptions
Enterprise
Contact Us
support@shodan.io
Shodan ® - All rights reserved