CVE-2021-32489: Integer Overflow
An issue was discovered in the sendsecuremsg() function of Yubico yubihsm-shell through 2.0.3. The function does not correctly validate the embedded length field of an authenticated message received from the device because responsemsg.st.len=8 can be accepted but triggers an integer overflow, which causes CRYPTOcbc128decrypt (in OpenSSL) to encounter an undersized buffer and experience a segmentation fault. The yubihsm-shell project is included in the YubiHSM 2 SDK product.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-32489.
What is the severity rating of CVE-2021-32489?
CVE-2021-32489 has a severity rating of 4.4 (medium).
What is the affected software for CVE-2021-32489?
The affected software for CVE-2021-32489 is Yubico yubihsm-shell version 2.0.3.
What is the CWE ID for CVE-2021-32489?
The CWE ID for CVE-2021-32489 is 190.
How can I fix CVE-2021-32489?
To fix CVE-2021-32489, it is recommended to update to a patched version of Yubico yubihsm-shell.