Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
An issue was discovered in the _send_secure_msg() function of Yubico yubihsm-shell through 2.0.3. The function does not correctly validate the embedded length field of an authenticated message received from the device. Out-of-bounds reads performed by aes_remove_padding() can crash the running process, depending on the memory layout. This could be used by an attacker to cause a client-side denial of service. The yubihsm-shell project is included in the YubiHSM 2 SDK product.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
yubihsm-shell 缓冲区错误漏洞
Vulnerability Description
yubihsm-shell是个人开发者的一个可与 YubiHSM 2 交互的组件。该组件大多存在于与 YubiHSM 2 交互的应用中,面向用户和程序级别的交互。 Yubico yubihsm-shell through 2.0.3 存在安全漏洞,该漏洞源于攻击者可利用该漏洞用来导致客户端拒绝服务。
CVSS Information
N/A
Vulnerability Type
N/A