#VU17735 Buffer overflow in libu2f-host - CVE-2018-20340
Published: February 18, 2019
libu2f-host
Yubico
Description
The vulnerability allows a physical attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error. An attacker with a custom made malicious USB device masquerading as a security key, and physical access to a computer where PAM U2F or an application with libu2f-host integrated can trigger buffer overflow and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.