MEDIUM
opensc: Buffer overflows handling responses from Gemsafe V1 Smartcards in pkcs15-gemsafeV1.c:gemsafe_get_cert_len()
Published Sep 3, 2018
6.8
MEDIUMCVSS 3.0
EPSS 0.65%
Description
Several buffer overflows when handling responses from a Gemsafe V1 Smartcard in gemsafe_get_cert_len in libopensc/pkcs15-gemsafeV1.c in OpenSC before 0.19.0-rc1 could be used by attackers able to supply crafted smartcards to cause a denial of service (application crash) or possibly have unspecified other impact.
Affected products
No data.
- ≤ 0.18.0
No data.
Red Hat Enterprise Linux 7
opensc-0:0.19.0-3.el7
Fixed · RHSA-2019:2154
Red Hat Enterprise Linux 8
opensc
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 | opensc-0:0.19.0-3.el7 | Fixed | RHSA-2019:2154 |
| Red Hat Enterprise Linux 8 | opensc | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (2)
References (9)
- https://access.redhat.com/errata/RHSA-2019:2154 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2018-16393 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1628006 Issue Tracking
- https://github.com/OpenSC/OpenSC/commit/360e95d45ac4123255a4c796db96337f332160ad x_refsource_MISCPatchThird Party Advisory
- https://github.com/OpenSC/OpenSC/releases/tag/0.19.0-rc1 x_refsource_MISCThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/09/msg00009.html mailing-listx_refsource_MLIST
- https://nvd.nist.gov/vuln/detail/CVE-2018-16393
- https://www.cve.org/CVERecord?id=CVE-2018-16393
- https://www.x41-dsec.de/lab/advisories/x41-2018-002-OpenSC/ x_refsource_MISCExploitThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/errata/RHSA-2019:2154 | vendor-advisoryx_refsource_REDHAT | |
| https://access.redhat.com/security/cve/CVE-2018-16393 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1628006 | Issue Tracking | |
| https://github.com/OpenSC/OpenSC/commit/360e95d45ac4123255a4c796db96337f332160ad | x_refsource_MISCPatchThird Party Advisory | |
| https://github.com/OpenSC/OpenSC/releases/tag/0.19.0-rc1 | x_refsource_MISCThird Party Advisory | |
| https://lists.debian.org/debian-lts-announce/2019/09/msg00009.html | mailing-listx_refsource_MLIST | |
| https://nvd.nist.gov/vuln/detail/CVE-2018-16393 | ||
| https://www.cve.org/CVERecord?id=CVE-2018-16393 | ||
| https://www.x41-dsec.de/lab/advisories/x41-2018-002-OpenSC/ | x_refsource_MISCExploitThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Sep 3, 2018
Updated Aug 5, 2024
Reserved Sep 3, 2018
Link CVE-2018-16393
CISA Vulnrichment
Updated n/a