Lucene search

K

Yubihsm-shell Security Vulnerabilities

cve
cve

CVE-2021-32489

An issue was discovered in the _send_secure_msg() function of Yubico yubihsm-shell through 2.0.3. The function does not correctly validate the embedded length field of an authenticated message received from the device because response_msg.st.len=8 can be accepted but triggers an integer overflow,.....

4.4CVSS

4.7AI Score

0.001EPSS

2021-05-10 10:15 PM
101
cve
cve

CVE-2021-27217

An issue was discovered in the _send_secure_msg() function of Yubico yubihsm-shell through 2.0.3. The function does not correctly validate the embedded length field of an authenticated message received from the device. Out-of-bounds reads performed by aes_remove_padding() can crash the running...

4.4CVSS

4.5AI Score

0.001EPSS

2021-03-04 06:15 PM
88
4
cve
cve

CVE-2020-24388

An issue was discovered in the _send_secure_msg() function of yubihsm-shell through 2.0.2. The function does not validate the embedded length field of a message received from the device. This could lead to an oversized memcpy() call that will crash the running process. This could be used by an...

7.5CVSS

7.2AI Score

0.007EPSS

2020-10-19 08:15 PM
91
cve
cve

CVE-2020-24387

An issue was discovered in the yh_create_session() function of yubihsm-shell through 2.0.2. The function does not explicitly check the returned session id from the device. An invalid session id would lead to out-of-bounds read and write operations in the session array. This could be used by an...

7.5CVSS

7.2AI Score

0.004EPSS

2020-10-19 08:15 PM
92