MEDIUM
opensc: Double free in coolkey_free_private_data in libopensc/card-coolkey.c
Published Apr 29, 2020
6.8
MEDIUMCVSS 3.1
EPSS 0.66%
Description
OpenSC before 0.20.0 has a double free in coolkey_free_private_data because coolkey_add_object in libopensc/card-coolkey.c lacks a uniqueness check.
Affected products
No data.
- < 0.20.0
No data.
Red Hat Enterprise Linux 8
opensc-0:0.20.0-2.el8
Fixed · RHSA-2020:4483
Red Hat Enterprise Linux 7
opensc
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | opensc-0:0.20.0-2.el8 | Fixed | RHSA-2020:4483 |
| Red Hat Enterprise Linux 7 | opensc | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat mitigation
If the coolkey driver is not necessary for the configuration and system in use, it is possible to disable it by not listing it in the /etc/opensc.conf file. For example: ``` app default { card_drivers = cac, cac1, PIV-II; } ```
Weaknesses (2)
References (8)
- https://access.redhat.com/security/cve/CVE-2019-20792 Vendor Advisory
- https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=19208 x_refsource_MISCExploitThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1837946 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-11329 Advisory
- https://github.com/OpenSC/OpenSC/commit/c246f6f69a749d4f68626b40795a4f69168008f4 x_refsource_MISCPatchThird Party Advisory
- https://github.com/OpenSC/OpenSC/compare/0.19.0...0.20.0 x_refsource_MISCRelease NotesThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-20792
- https://www.cve.org/CVERecord?id=CVE-2019-20792
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2019-20792 | Vendor Advisory | |
| https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=19208 | x_refsource_MISCExploitThird Party Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1837946 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-11329 | Advisory | |
| https://github.com/OpenSC/OpenSC/commit/c246f6f69a749d4f68626b40795a4f69168008f4 | x_refsource_MISCPatchThird Party Advisory | |
| https://github.com/OpenSC/OpenSC/compare/0.19.0...0.20.0 | x_refsource_MISCRelease NotesThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2019-20792 | ||
| https://www.cve.org/CVERecord?id=CVE-2019-20792 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Apr 29, 2020
Updated Aug 5, 2024
Reserved Apr 29, 2020
Link CVE-2019-20792
CISA Vulnrichment
No data
GitHub
No data