Advisory Database
  • Advisories
  • Dependency Scanning
  1. pypi
  2. ›
  3. cryptoauthlib
  4. ›
  5. GMS-2020-8

GMS-2020-8: Buffer overflow in deprecated USB HALs and stack overflow in USB enumeration

October 2, 2020 (updated October 4, 2021)

If an application is making use of the deprecated kit protocol HALs as the communication channel to the target device an attacker can masquerade as a device and return malformed packets of arbitrary length which the protocol stack will write to the stack.

References

  • github.com/MicrochipTech/cryptoauthlib/security/advisories/GHSA-f366-4rvv-95x2
  • github.com/advisories/GHSA-f366-4rvv-95x2

Code Behaviors & Features

Detect and mitigate GMS-2020-8 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 20200912

Fixed versions

  • 20200912

Solution

Upgrade to version 20200912 or above.

Source file

pypi/cryptoauthlib/GMS-2020-8.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 14 May 2025 12:14:48 +0000.