scheme/webauthn.c in Glewlwyd SSO server before 2.7.6 has a possible buffer overflow during FIDO2 credentials validation in webauthn registration.
[
{
"signature_type": "Line",
"deprecated": false,
"signature_version": "v1",
"target": {
"file": "src/scheme/webauthn.c"
},
"source": "https://github.com/babelouest/glewlwyd/commit/f9d8c06aae8dfe17e761b18b577ff169e059e812",
"digest": {
"line_hashes": [
"3126521908514980276993701937661429416",
"29460167690006000261515773344508394245",
"87246177665545369795529146646593038208",
"178857816088294456866092256009197415668",
"253239706193554113251102059820029890699",
"94868643169174739436906123308016492973",
"220479176731007184207716098956164154908",
"179946612665014277534457746097493345719",
"319460748058759492024994930827503141686",
"133578242049187467268492254494936622251"
],
"threshold": 0.9
},
"id": "CVE-2023-49208-4a55c754"
},
{
"signature_type": "Function",
"deprecated": false,
"signature_version": "v1",
"target": {
"file": "src/scheme/webauthn.c",
"function": "register_new_attestation"
},
"source": "https://github.com/babelouest/glewlwyd/commit/f9d8c06aae8dfe17e761b18b577ff169e059e812",
"digest": {
"length": 18374.0,
"function_hash": "37318830477182553963243962174868194257"
},
"id": "CVE-2023-49208-d01190f1"
}
]