{"affected":[{"ecosystem_specific":{"binaries":[{"libu2f-host-devel":"1.1.10-lp152.4.3.1","libu2f-host-doc":"1.1.10-lp152.4.3.1","libu2f-host0":"1.1.10-lp152.4.3.1","u2f-host":"1.1.10-lp152.4.3.1"}]},"package":{"ecosystem":"openSUSE:Leap 15.2","name":"libu2f-host","purl":"pkg:rpm/opensuse/libu2f-host&distro=openSUSE%20Leap%2015.2"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"1.1.10-lp152.4.3.1"}],"type":"ECOSYSTEM"}]}],"aliases":[],"details":"This update for libu2f-host fixes the following issues:\n\nThis update ships the u2f-host package (jsc#ECO-3687 bsc#1184648)\n\nVersion 1.1.10 (released 2019-05-15)\n\n- Add new devices to udev rules.\n- Fix a potentially uninitialized buffer (CVE-2019-9578, bsc#1128140)\n\nVersion 1.1.9 (released 2019-03-06)\n\n- Fix CID copying from the init response, which broke compatibility with\nsome devices.\n\nVersion 1.1.8 (released 2019-03-05)\n\n- Add udev rules\n- Drop 70-old-u2f.rules and use 70-u2f.rules for everything\n- Use a random nonce for setting up CID to prevent fingerprinting\n- CVE-2019-9578: Parse the response to init in a more stable way to prevent\n  leakage of uninitialized stack memory back to the device (bsc#1128140).\n\nVersion 1.1.7 (released 2019-01-08)\n\n- Fix for trusting length from device in device init.\n- Fix for buffer overflow when receiving data from device. (YSA-2019-01,\n  CVE-2018-20340, bsc#1124781)\n- Add udev rules for some new devices.\n\n- Add udev rule for Feitian ePass FIDO \n  - Add a timeout to the register and authenticate actions.\nThis update was imported from the SUSE:SLE-15:Update update project.","id":"openSUSE-SU-2021:0799-1","modified":"2021-05-28T16:05:18Z","published":"2021-05-28T16:05:18Z","references":[{"type":"ADVISORY","url":"https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/QRDOETNQVM5LVLJRZMNGQEBNRFW4ZWEV/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1124781"},{"type":"REPORT","url":"https://bugzilla.suse.com/1128140"},{"type":"REPORT","url":"https://bugzilla.suse.com/1184648"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-20340"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-9578"}],"related":["CVE-2018-20340","CVE-2019-9578"],"summary":"Security update for libu2f-host","upstream":["CVE-2018-20340","CVE-2019-9578"]}