CVE-2018-14779: Buffer Overflow
A buffer overflow issue was discovered in the Yubico-Piv 1.5.0 smartcard driver. The file lib/ykpiv.c contains the following code in the function ykpivtransferdata(): {% highlight c %} if(outlen + recvlen - 2 > maxout) { fprintf(stderr, "Output buffer to small, wanted to write %lu, max was %lu.", outlen + recvlen - 2, maxout); } if(outdata) { memcpy(outdata, data, recvlen - 2); outdata += recvlen - 2; outlen += recvlen - 2; } {% endhighlight %} -- it is clearly checked whether the buffer is big enough to hold the data copied using memcpy(), but no error handling happens to avoid the memcpy() in such cases. This code path can be triggered with malicious data coming from a smartcard.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2018-14779.
What is the severity of CVE-2018-14779?
The severity of CVE-2018-14779 is high with a CVSS score of 6.8.
How does CVE-2018-14779 affect Yubico-Piv?
CVE-2018-14779 affects Yubico-Piv 1.5.0.
How can I mitigate CVE-2018-14779?
To mitigate CVE-2018-14779, update to version 1.4.2-2ubuntu0.1 if you are using Ubuntu, or version 1.6.1-1 or 1.4.2-2+ if you are using a different distribution.
Where can I find more information about CVE-2018-14779?
You can find more information about CVE-2018-14779 at the following links: [link1](http://www.openwall.com/lists/oss-security/2018/08/14/2), [link2](https://usn.ubuntu.com/4276-1/), [link3](https://www.x41-dsec.de/lab/advisories/x41-2018-001-Yubico-Piv/).