Format String vulnerability in KeepKey version 4.0.0 allows attackers to trigger information display (of information that should not be accessible), related to text containing characters that the device's font lacks.
References
Link | Resource |
---|---|
https://www.keepkey.com/2018/03/09/security-updates-responsible-disclosure/ | Vendor Advisory |
https://www.keepkey.com/2018/03/09/security-updates-responsible-disclosure/ | Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
History
21 Nov 2024, 04:11
Type | Values Removed | Values Added |
---|---|---|
References | () https://www.keepkey.com/2018/03/09/security-updates-responsible-disclosure/ - Vendor Advisory |
Information
Published : 2018-03-14 13:29
Updated : 2024-11-21 04:11
NVD link : CVE-2018-6875
Mitre link : CVE-2018-6875
CVE.ORG link : CVE-2018-6875
JSON object : View
Products Affected
shapeshift
- keepkey_firmware
keepkey
- keepkey
CWE
CWE-134
Use of Externally-Controlled Format String