CVE-2020-24388: Input Validation
An issue was discovered in the sendsecuremsg() function of yubihsm-shell through 2.0.2. The function does not validate the embedded length field of a message received from the device. This could lead to an oversized memcpy() call that will crash the running process. This could be used by an attacker to cause a denial of service.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue in yubihsm-shell?
The vulnerability ID of this issue in yubihsm-shell is CVE-2020-24388.
What is the severity of CVE-2020-24388?
The severity of CVE-2020-24388 is high with a CVSS score of 7.5.
How does CVE-2020-24388 affect the Yubico yubihsm-shell?
CVE-2020-24388 affects the Yubico yubihsm-shell version up to and including 2.0.2.
What is the impact of CVE-2020-24388?
CVE-2020-24388 can lead to a crash of the running process due to an oversized memcpy() call.
How can I fix CVE-2020-24388?
To fix CVE-2020-24388, it is recommended to update to a version of yubihsm-shell that is not affected by the vulnerability.