Description
The Verify() method for FIDO/U2F security key types ([email protected], [email protected]) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.
Mitigation
Minimal update. May introduce new vulnerabilities or breaking changes.
|
 go | | | 0.52.0 |
 debian 12 | | =1:0.10.0-1 || =1:0.12.0-1 || =1:0.13.0-1 || =1:0.14.0-1 || =1:0.16.0-1 || =1:0.17.0-1 || =1:0.18.0-1 || =1:0.19.0-1 || =1:0.21.0-1 || =1:0.22.0-1 || =1:0.23.0-1 || =1:0.24.0-1 || =1:0.24.0-2 || =1:0.25.0-1 || =1:0.25.0-1~bpo12+1 || =1:0.33.0-1~exp1 || =1:0.36.0-1~exp1 || =1:0.4.0-1 || =1:0.41.0-1~exp1 || =1:0.42.0-1 || =1:0.42.0-1~exp1 || =1:0.42.0-2 || =1:0.42.0-3 || =1:0.42.0-4 || =1:0.43.0-1 || =1:0.43.0-2 || =1:0.45.0-1 || =1:0.46.0-1 || =1:0.47.0-1 || =1:0.50.0-1 || =1:0.52.0-1 | - |
 debian 11 | | =1:0.0~git20201221.eec23a3-1 || =1:0.0~git20210817.32db794-1 || =1:0.0~git20211202.5770296-1 || =1:0.0~git20220315.3147a52-1 || =1:0.0~git20220829.c86fa9a-1 || =1:0.0~git20220829.c86fa9a-1~bpo11+1 || =1:0.1.0-1 || =1:0.10.0-1 || =1:0.12.0-1 || =1:0.13.0-1 || =1:0.14.0-1 || =1:0.16.0-1 || =1:0.17.0-1 || =1:0.18.0-1 || =1:0.19.0-1 || =1:0.21.0-1 || =1:0.22.0-1 || =1:0.23.0-1 || =1:0.24.0-1 || =1:0.24.0-2 || =1:0.25.0-1 || =1:0.25.0-1~bpo12+1 || =1:0.33.0-1~exp1 || =1:0.36.0-1~exp1 || =1:0.4.0-1 || =1:0.41.0-1~exp1 || =1:0.42.0-1 || =1:0.42.0-1~exp1 || =1:0.42.0-2 || =1:0.42.0-3 || =1:0.42.0-4 || =1:0.43.0-1 || =1:0.43.0-2 || =1:0.45.0-1 || =1:0.46.0-1 || =1:0.47.0-1 || =1:0.50.0-1 || =1:0.52.0-1 | - |
 debian 13 | | =1:0.25.0-1 || =1:0.33.0-1~exp1 || =1:0.36.0-1~exp1 || =1:0.41.0-1~exp1 || =1:0.42.0-1 || =1:0.42.0-1~exp1 || =1:0.42.0-2 || =1:0.42.0-3 || =1:0.42.0-4 || =1:0.43.0-1 || =1:0.43.0-2 || =1:0.45.0-1 || =1:0.46.0-1 || =1:0.47.0-1 || =1:0.50.0-1 || =1:0.52.0-1 | - |
 debian 14 | | =1:0.25.0-1 || =1:0.33.0-1~exp1 || =1:0.36.0-1~exp1 || =1:0.41.0-1~exp1 || =1:0.42.0-1 || =1:0.42.0-1~exp1 || =1:0.42.0-2 || =1:0.42.0-3 || =1:0.42.0-4 || =1:0.43.0-1 || =1:0.43.0-2 || =1:0.45.0-1 || =1:0.46.0-1 || =1:0.47.0-1 || =1:0.50.0-1 || >=0 <1:0.52.0-1 | 1:0.52.0-1 |