Information leak via U2F #26
tsusanka
announced in
Past Security Issues
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
Details
The C/C++ reference implementation for U2F by Yubico contains broken definition of a struct which can leak bytes from RAM via USB. The bug was fixed by updating the structure definition to a new correct one.
Fix
trezor/trezor-firmware@0b26c52
Read more
Beta Was this translation helpful? Give feedback.
All reactions