CVE-2020-24387

CVE-2020-24387

An issue was discovered in the yh_create_session() function of yubihsm-shell through 2.0.2. The function does not explicitly check the returned session id from the device. An invalid session id would lead to out-of-bounds read and write operations in the session array. This could be used by an attacker to cause a denial of service attack.

Source: CVE-2020-24387

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다