CVE-2019-9578: High severity yubico libu2f-host vulnerability
In devs.c in Yubico libu2f-host before 1.1.8, the response to init is misparsed, leaking uninitialized stack memory back to the device.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2019-9578?
CVE-2019-9578 is a vulnerability in Yubico libu2f-host before version 1.1.8 that allows uninitialized stack memory to be leaked back to the device.
How does CVE-2019-9578 affect Yubico libu2f-host?
CVE-2019-9578 affects Yubico libu2f-host before version 1.1.8.
What is the severity of CVE-2019-9578?
The severity of CVE-2019-9578 is high with a CVSS score of 7.5.
How can I fix CVE-2019-9578?
To fix CVE-2019-9578, update Yubico libu2f-host to version 1.1.8 or later.
Where can I find more information about CVE-2019-9578?
You can find more information about CVE-2019-9578 in the following references: [link1](http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00012.html), [link2](http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00018.html), [link3](https://blog.inhq.net/posts/yubico-libu2f-host-vuln-part2/).