Format String vulnerability in KeepKey version 4.0.0 allows attackers to trigger information display (of information that should not be accessible), related to text containing characters that the device's font lacks.
References
Link | Resource |
---|---|
https://www.keepkey.com/2018/03/09/security-updates-responsible-disclosure/ | Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Information
Published : 2018-03-14 06:29
Updated : 2020-01-07 07:40
NVD link : CVE-2018-6875
Mitre link : CVE-2018-6875
JSON object : View
CWE
CWE-134
Use of Externally-Controlled Format String
Products Affected
shapeshift
- keepkey_firmware
keepkey
- keepkey