Oval Definition:oval:org.opensuse.security:def:66786
Revision Date:2021-05-25Version:1
Title:Security update for libu2f-host (Moderate)
Description:

This update for libu2f-host fixes the following issues:

This update ships the u2f-host package (jsc#ECO-3687 bsc#1184648)

Version 1.1.10 (released 2019-05-15)

* - Add new devices to udev rules. - Fix a potentially uninitialized buffer (CVE-2019-9578, bsc#1128140)

Version 1.1.9 (released 2019-03-06)

- Fix CID copying from the init response, which broke compatibility with some devices.

Version 1.1.8 (released 2019-03-05)

- Add udev rules - Drop 70-old-u2f.rules and use 70-u2f.rules for everything - Use a random nonce for setting up CID to prevent fingerprinting - CVE-2019-9578: Parse the response to init in a more stable way to prevent leakage of uninitialized stack memory back to the device (bsc#1128140).

Version 1.1.7 (released 2019-01-08)

- Fix for trusting length from device in device init. - Fix for buffer overflow when receiving data from device. (YSA-2019-01, CVE-2018-20340, bsc#1124781) - Add udev rules for some new devices.

- Add udev rule for Feitian ePass FIDO - Add a timeout to the register and authenticate actions.
Family:unixClass:patch
Status:Reference(s):1124781
1128140
1184648
CVE-2014-9638
CVE-2014-9639
CVE-2014-9640
CVE-2015-6749
CVE-2018-20340
CVE-2019-9578
CVE-2020-5208
Platform(s):SUSE Linux Enterprise Module for Desktop Applications 15 SP2
SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 SP2
SUSE Linux Enterprise Module for Server Applications 15 SP2
Product(s):
Definition Synopsis
  • SUSE Linux Enterprise Module for Desktop Applications 15 SP2 is installed
  • AND Package Information
  • vorbis-tools-1.4.0-1 is installed
  • OR vorbis-tools-lang-1.4.0-1 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Module for Server Applications 15 SP2 is installed
  • AND ipmitool-bmc-snmp-proxy-1.8.18+git20200204.7ccea28-1 is installed
  • BACK