cryptoauthlib
Python Wrapper Library for Microchip Security Products
Activity
- Latest release
- 4mo ago
- Total releases
- 45
- Cadence
- ~37 days
- Last 12 months
- 1
Details
- License
- custom
- First release
- Jul 19, 2018
| Version | Released | |
|---|---|---|
20260505
unknown
| ||
20250916
unknown
| ||
20250530
unknown
| ||
20250510
unknown
| ||
20250217
unknown
| ||
20250213
unknown
| ||
20241015
unknown
| ||
20240926
unknown
| ||
20240626
unknown
| ||
20230326
unknown
| ||
20230314
unknown
| ||
20221114
unknown
| ||
20221111
unknown
| ||
20221104
unknown
| ||
20221018
unknown
| ||
20220320
unknown
| ||
20211006
unknown
| ||
20210624
unknown
| ||
20210620
unknown
| ||
20210514
unknown
| ||
20210512
unknown
| ||
20210121
unknown
| ||
20210118
unknown
| ||
20210117
unknown
| ||
20210116
unknown
| ||
20201203
unknown
| ||
20201130
unknown
| ||
20200912
unknown
| ||
20200208
unknown
1 CVE
GHSA-f366-4rvv-95x2
Oct 02, 2020
Buffer overflow in deprecated USB HALs and stack overflow in USB enumeration
Low
Impact
PatchesUSB kit enumeration has been patched in v3.2.3 for the hidapi HAL (hal_all_platforms_kit_hidapi.c). Removal of deprecated HALsDeprecated usb kit HALs have been removed in v3.2.3. WorkaroundsThis vulnerability is limited to users of the kit protocol which is used with Microchip kits and kit firmware to bridge communication from USB-HID to I2C or SWI. It is not expected that kits would be used in an production environment. This is an optional component for users as well so they can always compile the library without the usb support option. Special python packaging notesThe python package for cryptoauthlib uses date codes for identifying versions. The patched version for python packages is 20200912 ReferencesPlease see Microchip PSIRT for Microchip's security policy and reporting procedures CreditsSpecial thanks to Ruben Santamarta of IOActive for reporting Affected versions
20180718
20180728
20180817
20181025
20181026
20181027
20190104
20190105
20190125
20190304
20190517
20190830
+ 5 more Show less
20190831
20190903
20191122
20200205
20200208
Fixed in
20200912
References Updated Dec 02, 2024 · Source: OSV.dev | ||
20200205
unknown
1 CVE
GHSA-f366-4rvv-95x2
Oct 02, 2020
Buffer overflow in deprecated USB HALs and stack overflow in USB enumeration
Low
Impact
PatchesUSB kit enumeration has been patched in v3.2.3 for the hidapi HAL (hal_all_platforms_kit_hidapi.c). Removal of deprecated HALsDeprecated usb kit HALs have been removed in v3.2.3. WorkaroundsThis vulnerability is limited to users of the kit protocol which is used with Microchip kits and kit firmware to bridge communication from USB-HID to I2C or SWI. It is not expected that kits would be used in an production environment. This is an optional component for users as well so they can always compile the library without the usb support option. Special python packaging notesThe python package for cryptoauthlib uses date codes for identifying versions. The patched version for python packages is 20200912 ReferencesPlease see Microchip PSIRT for Microchip's security policy and reporting procedures CreditsSpecial thanks to Ruben Santamarta of IOActive for reporting Affected versions
20180718
20180728
20180817
20181025
20181026
20181027
20190104
20190105
20190125
20190304
20190517
20190830
+ 5 more Show less
20190831
20190903
20191122
20200205
20200208
Fixed in
20200912
References Updated Dec 02, 2024 · Source: OSV.dev | ||
20191122
unknown
1 CVE
GHSA-f366-4rvv-95x2
Oct 02, 2020
Buffer overflow in deprecated USB HALs and stack overflow in USB enumeration
Low
Impact
PatchesUSB kit enumeration has been patched in v3.2.3 for the hidapi HAL (hal_all_platforms_kit_hidapi.c). Removal of deprecated HALsDeprecated usb kit HALs have been removed in v3.2.3. WorkaroundsThis vulnerability is limited to users of the kit protocol which is used with Microchip kits and kit firmware to bridge communication from USB-HID to I2C or SWI. It is not expected that kits would be used in an production environment. This is an optional component for users as well so they can always compile the library without the usb support option. Special python packaging notesThe python package for cryptoauthlib uses date codes for identifying versions. The patched version for python packages is 20200912 ReferencesPlease see Microchip PSIRT for Microchip's security policy and reporting procedures CreditsSpecial thanks to Ruben Santamarta of IOActive for reporting Affected versions
20180718
20180728
20180817
20181025
20181026
20181027
20190104
20190105
20190125
20190304
20190517
20190830
+ 5 more Show less
20190831
20190903
20191122
20200205
20200208
Fixed in
20200912
References Updated Dec 02, 2024 · Source: OSV.dev | ||
20190903
unknown
1 CVE
GHSA-f366-4rvv-95x2
Oct 02, 2020
Buffer overflow in deprecated USB HALs and stack overflow in USB enumeration
Low
Impact
PatchesUSB kit enumeration has been patched in v3.2.3 for the hidapi HAL (hal_all_platforms_kit_hidapi.c). Removal of deprecated HALsDeprecated usb kit HALs have been removed in v3.2.3. WorkaroundsThis vulnerability is limited to users of the kit protocol which is used with Microchip kits and kit firmware to bridge communication from USB-HID to I2C or SWI. It is not expected that kits would be used in an production environment. This is an optional component for users as well so they can always compile the library without the usb support option. Special python packaging notesThe python package for cryptoauthlib uses date codes for identifying versions. The patched version for python packages is 20200912 ReferencesPlease see Microchip PSIRT for Microchip's security policy and reporting procedures CreditsSpecial thanks to Ruben Santamarta of IOActive for reporting Affected versions
20180718
20180728
20180817
20181025
20181026
20181027
20190104
20190105
20190125
20190304
20190517
20190830
+ 5 more Show less
20190831
20190903
20191122
20200205
20200208
Fixed in
20200912
References Updated Dec 02, 2024 · Source: OSV.dev | ||
20190831
unknown
1 CVE
GHSA-f366-4rvv-95x2
Oct 02, 2020
Buffer overflow in deprecated USB HALs and stack overflow in USB enumeration
Low
Impact
PatchesUSB kit enumeration has been patched in v3.2.3 for the hidapi HAL (hal_all_platforms_kit_hidapi.c). Removal of deprecated HALsDeprecated usb kit HALs have been removed in v3.2.3. WorkaroundsThis vulnerability is limited to users of the kit protocol which is used with Microchip kits and kit firmware to bridge communication from USB-HID to I2C or SWI. It is not expected that kits would be used in an production environment. This is an optional component for users as well so they can always compile the library without the usb support option. Special python packaging notesThe python package for cryptoauthlib uses date codes for identifying versions. The patched version for python packages is 20200912 ReferencesPlease see Microchip PSIRT for Microchip's security policy and reporting procedures CreditsSpecial thanks to Ruben Santamarta of IOActive for reporting Affected versions
20180718
20180728
20180817
20181025
20181026
20181027
20190104
20190105
20190125
20190304
20190517
20190830
+ 5 more Show less
20190831
20190903
20191122
20200205
20200208
Fixed in
20200912
References Updated Dec 02, 2024 · Source: OSV.dev | ||
20190830
unknown
1 CVE
GHSA-f366-4rvv-95x2
Oct 02, 2020
Buffer overflow in deprecated USB HALs and stack overflow in USB enumeration
Low
Impact
PatchesUSB kit enumeration has been patched in v3.2.3 for the hidapi HAL (hal_all_platforms_kit_hidapi.c). Removal of deprecated HALsDeprecated usb kit HALs have been removed in v3.2.3. WorkaroundsThis vulnerability is limited to users of the kit protocol which is used with Microchip kits and kit firmware to bridge communication from USB-HID to I2C or SWI. It is not expected that kits would be used in an production environment. This is an optional component for users as well so they can always compile the library without the usb support option. Special python packaging notesThe python package for cryptoauthlib uses date codes for identifying versions. The patched version for python packages is 20200912 ReferencesPlease see Microchip PSIRT for Microchip's security policy and reporting procedures CreditsSpecial thanks to Ruben Santamarta of IOActive for reporting Affected versions
20180718
20180728
20180817
20181025
20181026
20181027
20190104
20190105
20190125
20190304
20190517
20190830
+ 5 more Show less
20190831
20190903
20191122
20200205
20200208
Fixed in
20200912
References Updated Dec 02, 2024 · Source: OSV.dev | ||
20190517
unknown
1 CVE
GHSA-f366-4rvv-95x2
Oct 02, 2020
Buffer overflow in deprecated USB HALs and stack overflow in USB enumeration
Low
Impact
PatchesUSB kit enumeration has been patched in v3.2.3 for the hidapi HAL (hal_all_platforms_kit_hidapi.c). Removal of deprecated HALsDeprecated usb kit HALs have been removed in v3.2.3. WorkaroundsThis vulnerability is limited to users of the kit protocol which is used with Microchip kits and kit firmware to bridge communication from USB-HID to I2C or SWI. It is not expected that kits would be used in an production environment. This is an optional component for users as well so they can always compile the library without the usb support option. Special python packaging notesThe python package for cryptoauthlib uses date codes for identifying versions. The patched version for python packages is 20200912 ReferencesPlease see Microchip PSIRT for Microchip's security policy and reporting procedures CreditsSpecial thanks to Ruben Santamarta of IOActive for reporting Affected versions
20180718
20180728
20180817
20181025
20181026
20181027
20190104
20190105
20190125
20190304
20190517
20190830
+ 5 more Show less
20190831
20190903
20191122
20200205
20200208
Fixed in
20200912
References Updated Dec 02, 2024 · Source: OSV.dev | ||
20190304
unknown
1 CVE
GHSA-f366-4rvv-95x2
Oct 02, 2020
Buffer overflow in deprecated USB HALs and stack overflow in USB enumeration
Low
Impact
PatchesUSB kit enumeration has been patched in v3.2.3 for the hidapi HAL (hal_all_platforms_kit_hidapi.c). Removal of deprecated HALsDeprecated usb kit HALs have been removed in v3.2.3. WorkaroundsThis vulnerability is limited to users of the kit protocol which is used with Microchip kits and kit firmware to bridge communication from USB-HID to I2C or SWI. It is not expected that kits would be used in an production environment. This is an optional component for users as well so they can always compile the library without the usb support option. Special python packaging notesThe python package for cryptoauthlib uses date codes for identifying versions. The patched version for python packages is 20200912 ReferencesPlease see Microchip PSIRT for Microchip's security policy and reporting procedures CreditsSpecial thanks to Ruben Santamarta of IOActive for reporting Affected versions
20180718
20180728
20180817
20181025
20181026
20181027
20190104
20190105
20190125
20190304
20190517
20190830
+ 5 more Show less
20190831
20190903
20191122
20200205
20200208
Fixed in
20200912
References Updated Dec 02, 2024 · Source: OSV.dev | ||
20190125
unknown
1 CVE
GHSA-f366-4rvv-95x2
Oct 02, 2020
Buffer overflow in deprecated USB HALs and stack overflow in USB enumeration
Low
Impact
PatchesUSB kit enumeration has been patched in v3.2.3 for the hidapi HAL (hal_all_platforms_kit_hidapi.c). Removal of deprecated HALsDeprecated usb kit HALs have been removed in v3.2.3. WorkaroundsThis vulnerability is limited to users of the kit protocol which is used with Microchip kits and kit firmware to bridge communication from USB-HID to I2C or SWI. It is not expected that kits would be used in an production environment. This is an optional component for users as well so they can always compile the library without the usb support option. Special python packaging notesThe python package for cryptoauthlib uses date codes for identifying versions. The patched version for python packages is 20200912 ReferencesPlease see Microchip PSIRT for Microchip's security policy and reporting procedures CreditsSpecial thanks to Ruben Santamarta of IOActive for reporting Affected versions
20180718
20180728
20180817
20181025
20181026
20181027
20190104
20190105
20190125
20190304
20190517
20190830
+ 5 more Show less
20190831
20190903
20191122
20200205
20200208
Fixed in
20200912
References Updated Dec 02, 2024 · Source: OSV.dev | ||
20190105
unknown
1 CVE
GHSA-f366-4rvv-95x2
Oct 02, 2020
Buffer overflow in deprecated USB HALs and stack overflow in USB enumeration
Low
Impact
PatchesUSB kit enumeration has been patched in v3.2.3 for the hidapi HAL (hal_all_platforms_kit_hidapi.c). Removal of deprecated HALsDeprecated usb kit HALs have been removed in v3.2.3. WorkaroundsThis vulnerability is limited to users of the kit protocol which is used with Microchip kits and kit firmware to bridge communication from USB-HID to I2C or SWI. It is not expected that kits would be used in an production environment. This is an optional component for users as well so they can always compile the library without the usb support option. Special python packaging notesThe python package for cryptoauthlib uses date codes for identifying versions. The patched version for python packages is 20200912 ReferencesPlease see Microchip PSIRT for Microchip's security policy and reporting procedures CreditsSpecial thanks to Ruben Santamarta of IOActive for reporting Affected versions
20180718
20180728
20180817
20181025
20181026
20181027
20190104
20190105
20190125
20190304
20190517
20190830
+ 5 more Show less
20190831
20190903
20191122
20200205
20200208
Fixed in
20200912
References Updated Dec 02, 2024 · Source: OSV.dev | ||
20190104
unknown
1 CVE
GHSA-f366-4rvv-95x2
Oct 02, 2020
Buffer overflow in deprecated USB HALs and stack overflow in USB enumeration
Low
Impact
PatchesUSB kit enumeration has been patched in v3.2.3 for the hidapi HAL (hal_all_platforms_kit_hidapi.c). Removal of deprecated HALsDeprecated usb kit HALs have been removed in v3.2.3. WorkaroundsThis vulnerability is limited to users of the kit protocol which is used with Microchip kits and kit firmware to bridge communication from USB-HID to I2C or SWI. It is not expected that kits would be used in an production environment. This is an optional component for users as well so they can always compile the library without the usb support option. Special python packaging notesThe python package for cryptoauthlib uses date codes for identifying versions. The patched version for python packages is 20200912 ReferencesPlease see Microchip PSIRT for Microchip's security policy and reporting procedures CreditsSpecial thanks to Ruben Santamarta of IOActive for reporting Affected versions
20180718
20180728
20180817
20181025
20181026
20181027
20190104
20190105
20190125
20190304
20190517
20190830
+ 5 more Show less
20190831
20190903
20191122
20200205
20200208
Fixed in
20200912
References Updated Dec 02, 2024 · Source: OSV.dev | ||
20181027
unknown
1 CVE
GHSA-f366-4rvv-95x2
Oct 02, 2020
Buffer overflow in deprecated USB HALs and stack overflow in USB enumeration
Low
Impact
PatchesUSB kit enumeration has been patched in v3.2.3 for the hidapi HAL (hal_all_platforms_kit_hidapi.c). Removal of deprecated HALsDeprecated usb kit HALs have been removed in v3.2.3. WorkaroundsThis vulnerability is limited to users of the kit protocol which is used with Microchip kits and kit firmware to bridge communication from USB-HID to I2C or SWI. It is not expected that kits would be used in an production environment. This is an optional component for users as well so they can always compile the library without the usb support option. Special python packaging notesThe python package for cryptoauthlib uses date codes for identifying versions. The patched version for python packages is 20200912 ReferencesPlease see Microchip PSIRT for Microchip's security policy and reporting procedures CreditsSpecial thanks to Ruben Santamarta of IOActive for reporting Affected versions
20180718
20180728
20180817
20181025
20181026
20181027
20190104
20190105
20190125
20190304
20190517
20190830
+ 5 more Show less
20190831
20190903
20191122
20200205
20200208
Fixed in
20200912
References Updated Dec 02, 2024 · Source: OSV.dev | ||
20181026
unknown
1 CVE
GHSA-f366-4rvv-95x2
Oct 02, 2020
Buffer overflow in deprecated USB HALs and stack overflow in USB enumeration
Low
Impact
PatchesUSB kit enumeration has been patched in v3.2.3 for the hidapi HAL (hal_all_platforms_kit_hidapi.c). Removal of deprecated HALsDeprecated usb kit HALs have been removed in v3.2.3. WorkaroundsThis vulnerability is limited to users of the kit protocol which is used with Microchip kits and kit firmware to bridge communication from USB-HID to I2C or SWI. It is not expected that kits would be used in an production environment. This is an optional component for users as well so they can always compile the library without the usb support option. Special python packaging notesThe python package for cryptoauthlib uses date codes for identifying versions. The patched version for python packages is 20200912 ReferencesPlease see Microchip PSIRT for Microchip's security policy and reporting procedures CreditsSpecial thanks to Ruben Santamarta of IOActive for reporting Affected versions
20180718
20180728
20180817
20181025
20181026
20181027
20190104
20190105
20190125
20190304
20190517
20190830
+ 5 more Show less
20190831
20190903
20191122
20200205
20200208
Fixed in
20200912
References Updated Dec 02, 2024 · Source: OSV.dev | ||
20181025
unknown
1 CVE
GHSA-f366-4rvv-95x2
Oct 02, 2020
Buffer overflow in deprecated USB HALs and stack overflow in USB enumeration
Low
Impact
PatchesUSB kit enumeration has been patched in v3.2.3 for the hidapi HAL (hal_all_platforms_kit_hidapi.c). Removal of deprecated HALsDeprecated usb kit HALs have been removed in v3.2.3. WorkaroundsThis vulnerability is limited to users of the kit protocol which is used with Microchip kits and kit firmware to bridge communication from USB-HID to I2C or SWI. It is not expected that kits would be used in an production environment. This is an optional component for users as well so they can always compile the library without the usb support option. Special python packaging notesThe python package for cryptoauthlib uses date codes for identifying versions. The patched version for python packages is 20200912 ReferencesPlease see Microchip PSIRT for Microchip's security policy and reporting procedures CreditsSpecial thanks to Ruben Santamarta of IOActive for reporting Affected versions
20180718
20180728
20180817
20181025
20181026
20181027
20190104
20190105
20190125
20190304
20190517
20190830
+ 5 more Show less
20190831
20190903
20191122
20200205
20200208
Fixed in
20200912
References Updated Dec 02, 2024 · Source: OSV.dev | ||
20180817
unknown
1 CVE
GHSA-f366-4rvv-95x2
Oct 02, 2020
Buffer overflow in deprecated USB HALs and stack overflow in USB enumeration
Low
Impact
PatchesUSB kit enumeration has been patched in v3.2.3 for the hidapi HAL (hal_all_platforms_kit_hidapi.c). Removal of deprecated HALsDeprecated usb kit HALs have been removed in v3.2.3. WorkaroundsThis vulnerability is limited to users of the kit protocol which is used with Microchip kits and kit firmware to bridge communication from USB-HID to I2C or SWI. It is not expected that kits would be used in an production environment. This is an optional component for users as well so they can always compile the library without the usb support option. Special python packaging notesThe python package for cryptoauthlib uses date codes for identifying versions. The patched version for python packages is 20200912 ReferencesPlease see Microchip PSIRT for Microchip's security policy and reporting procedures CreditsSpecial thanks to Ruben Santamarta of IOActive for reporting Affected versions
20180718
20180728
20180817
20181025
20181026
20181027
20190104
20190105
20190125
20190304
20190517
20190830
+ 5 more Show less
20190831
20190903
20191122
20200205
20200208
Fixed in
20200912
References Updated Dec 02, 2024 · Source: OSV.dev | ||
20180728
unknown
1 CVE
GHSA-f366-4rvv-95x2
Oct 02, 2020
Buffer overflow in deprecated USB HALs and stack overflow in USB enumeration
Low
Impact
PatchesUSB kit enumeration has been patched in v3.2.3 for the hidapi HAL (hal_all_platforms_kit_hidapi.c). Removal of deprecated HALsDeprecated usb kit HALs have been removed in v3.2.3. WorkaroundsThis vulnerability is limited to users of the kit protocol which is used with Microchip kits and kit firmware to bridge communication from USB-HID to I2C or SWI. It is not expected that kits would be used in an production environment. This is an optional component for users as well so they can always compile the library without the usb support option. Special python packaging notesThe python package for cryptoauthlib uses date codes for identifying versions. The patched version for python packages is 20200912 ReferencesPlease see Microchip PSIRT for Microchip's security policy and reporting procedures CreditsSpecial thanks to Ruben Santamarta of IOActive for reporting Affected versions
20180718
20180728
20180817
20181025
20181026
20181027
20190104
20190105
20190125
20190304
20190517
20190830
+ 5 more Show less
20190831
20190903
20191122
20200205
20200208
Fixed in
20200912
References Updated Dec 02, 2024 · Source: OSV.dev | ||
20180718
unknown
1 CVE
GHSA-f366-4rvv-95x2
Oct 02, 2020
Buffer overflow in deprecated USB HALs and stack overflow in USB enumeration
Low
Impact
PatchesUSB kit enumeration has been patched in v3.2.3 for the hidapi HAL (hal_all_platforms_kit_hidapi.c). Removal of deprecated HALsDeprecated usb kit HALs have been removed in v3.2.3. WorkaroundsThis vulnerability is limited to users of the kit protocol which is used with Microchip kits and kit firmware to bridge communication from USB-HID to I2C or SWI. It is not expected that kits would be used in an production environment. This is an optional component for users as well so they can always compile the library without the usb support option. Special python packaging notesThe python package for cryptoauthlib uses date codes for identifying versions. The patched version for python packages is 20200912 ReferencesPlease see Microchip PSIRT for Microchip's security policy and reporting procedures CreditsSpecial thanks to Ruben Santamarta of IOActive for reporting Affected versions
20180718
20180728
20180817
20181025
20181026
20181027
20190104
20190105
20190125
20190304
20190517
20190830
+ 5 more Show less
20190831
20190903
20191122
20200205
20200208
Fixed in
20200912
References Updated Dec 02, 2024 · Source: OSV.dev |