Input validation error in YubiHSM2 SDK and yubihsm-shell - CVE-2020-24388
Published: October 19, 2020
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input within yubihsm-shell library, which is part of the YubiHSM2 SDK. A maliciously-crafted YubiHSM2 device, or someone with access to the HTTP traffic between a client and server handling the device, could cause the yubihsm library to crash.
Affected software
yubihsm-shell
Fedora
yubihsm-shell
How to mitigate CVE-2020-24388
yubihsm-shell - update to 2.0.3-1.fc33