scheme/webauthn.c in Glewlwyd SSO server 2.x before 2.6.2 has a buffer overflow associated with a webauthn assertion.
{ "vanir_signatures": [ { "signature_version": "v1", "digest": { "threshold": 0.9, "line_hashes": [ "220808046081210396080077479638927040481", "57273834636401937923658788307504268900", "313108989129243707049059965441053762188", "228164923958231496861717270284664263050", "234309396422907365673195692716210437506", "231881941146739342230003207148563531694", "169004794240369310944560637058773310332", "336525734495495921256508124459061621204" ] }, "deprecated": false, "id": "CVE-2022-27240-63f1fb6a", "source": "https://github.com/babelouest/glewlwyd/commit/4c5597c155bfbaf6491cf6b83479d241ae66940a", "signature_type": "Line", "target": { "file": "src/scheme/webauthn.c" } }, { "signature_version": "v1", "digest": { "length": 10261.0, "function_hash": "57275488854267954372487593094167411292" }, "deprecated": false, "id": "CVE-2022-27240-9a76c3ff", "source": "https://github.com/babelouest/glewlwyd/commit/4c5597c155bfbaf6491cf6b83479d241ae66940a", "signature_type": "Function", "target": { "function": "check_assertion", "file": "src/scheme/webauthn.c" } } ] }