PT-2020-15724 · Yubico · Yubihsm-Shell
Christian Reitter
·
Published
2020-10-19
·
Updated
2021-07-21
·
CVE-2020-24387
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
yubihsm-shell versions prior to 2.0.3
Description
An issue in the yh create session() function allows an attacker to cause a denial of service attack by exploiting out-of-bounds read and write operations in the session array. This occurs when the function fails to explicitly check the returned session id from the device, potentially leading to an invalid session id.
Recommendations
For yubihsm-shell versions prior to 2.0.3, update to version 2.0.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the yh create session() function until a patch is available.
Exploit
Fix
Out of bounds Read
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Yubihsm-Shell