Oval Definition:oval:org.opensuse.security:def:64506
Revision Date:2021-05-25Version:1
Title:Security update for libu2f-host (Moderate)
Description:

This update for libu2f-host fixes the following issues:

This update ships the u2f-host package (jsc#ECO-3687 bsc#1184648)

Version 1.1.10 (released 2019-05-15)

* - Add new devices to udev rules. - Fix a potentially uninitialized buffer (CVE-2019-9578, bsc#1128140)

Version 1.1.9 (released 2019-03-06)

- Fix CID copying from the init response, which broke compatibility with some devices.

Version 1.1.8 (released 2019-03-05)

- Add udev rules - Drop 70-old-u2f.rules and use 70-u2f.rules for everything - Use a random nonce for setting up CID to prevent fingerprinting - CVE-2019-9578: Parse the response to init in a more stable way to prevent leakage of uninitialized stack memory back to the device (bsc#1128140).

Version 1.1.7 (released 2019-01-08)

- Fix for trusting length from device in device init. - Fix for buffer overflow when receiving data from device. (YSA-2019-01, CVE-2018-20340, bsc#1124781) - Add udev rules for some new devices.

- Add udev rule for Feitian ePass FIDO - Add a timeout to the register and authenticate actions.
Family:unixClass:patch
Status:Reference(s):1115645
1124781
1128140
1154817
1163102
1163103
1163104
1163927
1173202
1173274
1175109
1176590
1178593
1184648
CVE-2015-5198
CVE-2015-5199
CVE-2015-5200
CVE-2016-3714
CVE-2016-3715
CVE-2016-3716
CVE-2016-3717
CVE-2016-3718
CVE-2016-5118
CVE-2017-18926
CVE-2018-10805
CVE-2018-11624
CVE-2018-11625
CVE-2018-12599
CVE-2018-12600
CVE-2018-14434
CVE-2018-14435
CVE-2018-14436
CVE-2018-14437
CVE-2018-16323
CVE-2018-16328
CVE-2018-16329
CVE-2018-16412
CVE-2018-16413
CVE-2018-16640
CVE-2018-16641
CVE-2018-16642
CVE-2018-16643
CVE-2018-16644
CVE-2018-16645
CVE-2018-17966
CVE-2018-18024
CVE-2018-18544
CVE-2018-20340
CVE-2018-20467
CVE-2018-9135
CVE-2019-10650
CVE-2019-11007
CVE-2019-11008
CVE-2019-14559
CVE-2019-15604
CVE-2019-15605
CVE-2019-15606
CVE-2019-7175
CVE-2019-7395
CVE-2019-7396
CVE-2019-7397
CVE-2019-7398
CVE-2019-9578
CVE-2019-9956
CVE-2020-14374
CVE-2020-14375
CVE-2020-14376
CVE-2020-14377
CVE-2020-14378
CVE-2020-14422
CVE-2020-1967
CVE-2020-8231
openSUSE-SU-2020:0293-1
openSUSE-SU-2020:0622-1
openSUSE-SU-2020:0931-1
openSUSE-SU-2020:0933-1
openSUSE-SU-2020:1345-1
openSUSE-SU-2020:1599-1
SUSE-SU-2021:1755-1
Platform(s):openSUSE Leap 15.1
openSUSE Leap 15.2
SUSE Linux Enterprise Desktop 15 SP2
SUSE Linux Enterprise High Performance Computing 15 SP2
SUSE Linux Enterprise Module for Basesystem 15 SP2
SUSE Linux Enterprise Module for Desktop Applications 15 SP1
SUSE Linux Enterprise Server 15 SP2
SUSE Linux Enterprise Server for SAP Applications 15 SP2
SUSE Linux Enterprise Storage 7
SUSE Manager Proxy 4.1
SUSE Manager Server 4.1
Product(s):
Definition Synopsis
  • openSUSE Leap 15.1 is installed
  • AND Package Information
  • curl-7.60.0-lp151.5.15 is installed
  • OR curl-mini-7.60.0-lp151.5.15 is installed
  • OR libcurl-devel-7.60.0-lp151.5.15 is installed
  • OR libcurl-devel-32bit-7.60.0-lp151.5.15 is installed
  • OR libcurl-mini-devel-7.60.0-lp151.5.15 is installed
  • OR libcurl4-7.60.0-lp151.5.15 is installed
  • OR libcurl4-32bit-7.60.0-lp151.5.15 is installed
  • OR libcurl4-mini-7.60.0-lp151.5.15 is installed
  • Definition Synopsis
  • openSUSE Leap 15.2 is installed
  • AND Package Information
  • dpdk-19.11.4-lp152.2.8 is installed
  • OR dpdk-devel-19.11.4-lp152.2.8 is installed
  • OR dpdk-doc-19.11.4-lp152.2.8 is installed
  • OR dpdk-examples-19.11.4-lp152.2.8 is installed
  • OR dpdk-kmp-default-19.11.4_k5.3.18_lp152.41-lp152.2.8 is installed
  • OR dpdk-kmp-preempt-19.11.4_k5.3.18_lp152.41-lp152.2.8 is installed
  • OR dpdk-tools-19.11.4-lp152.2.8 is installed
  • OR libdpdk-20_0-19.11.4-lp152.2.8 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Module for Basesystem 15 SP2 is installed
  • AND Package Information
  • libu2f-host-devel-1.1.10-3.9.1 is installed
  • OR libu2f-host0-1.1.10-3.9.1 is installed
  • OR u2f-host-1.1.10-3.9.1 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Module for Desktop Applications 15 SP1 is installed
  • AND Package Information
  • ImageMagick-7.0.7.34-3.54 is installed
  • OR ImageMagick-config-7-SUSE-7.0.7.34-3.54 is installed
  • OR ImageMagick-devel-7.0.7.34-3.54 is installed
  • OR libMagick++-7_Q16HDRI4-7.0.7.34-3.54 is installed
  • OR libMagick++-devel-7.0.7.34-3.54 is installed
  • OR libMagickCore-7_Q16HDRI6-7.0.7.34-3.54 is installed
  • OR libMagickWand-7_Q16HDRI6-7.0.7.34-3.54 is installed
  • BACK