An issue was discovered in Yubico libykpiv before 2.1.0. An attacker can trigger an incorrect free() in the ykpiv_util_generate_key() function in lib/util.c through incorrect error handling code. This could be used to cause a denial of service attack.
2020-07-09T18:15:10.663
2024-11-21T05:00:43.417
Modified
CVSSv3.1: 4.6 (MEDIUM)
AV:L/AC:L/Au:N/C:N/I:N/A:P
3.9
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | yubico | libykpiv | < 2.1.0 | Yes |
Application | yubico | piv_tool_manager | < 2.0.0 | Yes |
Application | yubico | yubikey_smart_card_minidriver | ≤ 4.1.0.172 | Yes |