Format String vulnerability in KeepKey version 4.0.0 allows attackers to trigger information display (of information that should not be accessible), related to text containing characters that the device's font lacks.
References
Link | Resource |
---|---|
https://www.keepkey.com/2018/03/09/security-updates-responsible-disclosure/ | Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
History
No history.
Information
Published : 2018-03-14 13:29
Updated : 2020-01-07 15:40
NVD link : CVE-2018-6875
Mitre link : CVE-2018-6875
CVE.ORG link : CVE-2018-6875
JSON object : View
Products Affected
keepkey
- keepkey
shapeshift
- keepkey_firmware
CWE
CWE-134
Use of Externally-Controlled Format String