MEDIUM
opensc: Buffer overflows handling responses from CAC Cards in card-cac.c:cac_get_serial_nr_from_CUID()
Published Sep 4, 2018
6.6
MEDIUMCVSS 3.0
EPSS 0.72%
Description
Several buffer overflows when handling responses from a CAC Card in cac_get_serial_nr_from_CUID in libopensc/card-cac.c in OpenSC before 0.19.0-rc1 could be used by attackers able to supply crafted smartcards to cause a denial of service (application crash) or possibly have unspecified other impact.
Affected products
No data.
- ≤ 0.18.0
No data.
Red Hat Enterprise Linux 7
opensc-0:0.19.0-3.el7
Fixed · RHSA-2019:2154
Red Hat Enterprise Linux 8
opensc
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 | opensc-0:0.19.0-3.el7 | Fixed | RHSA-2019:2154 |
| Red Hat Enterprise Linux 8 | opensc | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (2)
References (10)
- https://access.redhat.com/errata/RHSA-2019:2154 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2018-16421 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1628034 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2018-8261 Advisory
- https://github.com/OpenSC/OpenSC/commit/360e95d45ac4123255a4c796db96337f332160ad#diff-848b13147a344ba2c6361d91ca77feb1 x_refsource_MISCPatchThird Party Advisory
- https://github.com/OpenSC/OpenSC/releases/tag/0.19.0-rc1 x_refsource_MISCPatchRelease NotesThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/09/msg00009.html mailing-listx_refsource_MLIST
- https://nvd.nist.gov/vuln/detail/CVE-2018-16421
- https://www.cve.org/CVERecord?id=CVE-2018-16421
- https://www.x41-dsec.de/lab/advisories/x41-2018-002-OpenSC/ x_refsource_MISCExploitThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/errata/RHSA-2019:2154 | vendor-advisoryx_refsource_REDHAT | |
| https://access.redhat.com/security/cve/CVE-2018-16421 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1628034 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2018-8261 | Advisory | |
| https://github.com/OpenSC/OpenSC/commit/360e95d45ac4123255a4c796db96337f332160ad#diff-848b13147a344ba2c6361d91ca77feb1 | x_refsource_MISCPatchThird Party Advisory | |
| https://github.com/OpenSC/OpenSC/releases/tag/0.19.0-rc1 | x_refsource_MISCPatchRelease NotesThird Party Advisory | |
| https://lists.debian.org/debian-lts-announce/2019/09/msg00009.html | mailing-listx_refsource_MLIST | |
| https://nvd.nist.gov/vuln/detail/CVE-2018-16421 | ||
| https://www.cve.org/CVERecord?id=CVE-2018-16421 | ||
| https://www.x41-dsec.de/lab/advisories/x41-2018-002-OpenSC/ | x_refsource_MISCExploitThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Sep 4, 2018
Updated Aug 5, 2024
Reserved Sep 3, 2018
Link CVE-2018-16421
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2018-8261 Assigner mitre
Published Sep 4, 2018
Updated Aug 5, 2024
Exploited since n/a
Link EUVD-2018-8261