Purchase Linux CDs / DVDs / Flash Drives at OSDisc.com

Welcome to Our Community

While Linux.org has been around for a while, we recently changed management and had to purge most of the content (including users). If you signed up before April 23rd, 2017 please sign up again. Thanks!

  1. More ways to get the info! - we shoot all of our new original content out as well as random messages on Twitter and our newsletter!. Twitter | Newsletter
    Dismiss Notice

Debian Security Update DSA-4389 libu2f-host - security update

Discussion in 'Linux Security Announcements (Automated)' started by LinuxBot, Feb 11, 2019.

  1. LinuxBot

    LinuxBot Moderator
    Staff Member

    Joined:
    Apr 25, 2017
    Messages:
    30
    Likes Received:
    1
    Christian Reitter discovered that libu2f-host, a library implementing the host-side of the U2F protocol, failed to properly check for a buffer overflow. This would allow an attacker with a custom made malicious USB device masquerading as a security key, and physical access to a computer where PAM U2F or an application with libu2f-host integrated, to potentially execute arbitrary code on that computer.


    (Log in to hide this advertisement)


    Continue reading...
     

Share This Page