VYPR
Medium severity4.6NVD Advisory· Published Jul 9, 2020· Updated Jun 17, 2026

CVE-2020-13132

CVE-2020-13132

Description

An issue was discovered in Yubico libykpiv before 2.1.0. An attacker can trigger an incorrect free() in the ykpiv_util_generate_key() function in lib/util.c through incorrect error handling code. This could be used to cause a denial of service attack.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

5
  • Yubico/libykpiv2 versions
    cpe:2.3:a:yubico:libykpiv:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:yubico:libykpiv:*:*:*:*:*:*:*:*range: <2.1.0
    • (no CPE)range: <2.1.0
  • cpe:2.3:a:yubico:piv_tool_manager:*:*:*:*:*:*:*:*
    Range: <2.0.0
  • cpe:2.3:a:yubico:yubikey_smart_card_minidriver:*:*:*:*:*:*:*:*
    Range: <=4.1.0.172
  • Yubico/libykpivdescription

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.