In devs.c in Yubico libu2f-host before 1.1.8, the response to init is misparsed, leaking uninitialized stack memory back to the device.
The product uses or accesses a resource that has not been initialized.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Libu2f-host | Yubico | * | 1.1.8 (excluding) |
Libu2f-host | Ubuntu | bionic | * |
Libu2f-host | Ubuntu | cosmic | * |
Libu2f-host | Ubuntu | disco | * |
Libu2f-host | Ubuntu | esm-apps/xenial | * |
Libu2f-host | Ubuntu | esm-infra/bionic | * |
Libu2f-host | Ubuntu | xenial | * |