Vulnerability CVE-2018-16424: Information
Description
A double free when handling responses in read_file in tools/egk-tool.c (aka the eGK card tool) in OpenSC before 0.19.0-rc1 could be used by attackers able to supply crafted smartcards to cause a denial of service (application crash) or possibly have unspecified other impact.
Severity: MEDIUM (6.6) Vector: CVSS:3.0/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Fixed packages
Package name | Branch | Fixed in version | Version from repository | Errata ID | Task # | State |
---|---|---|---|---|---|---|
opensc | sisyphus | 0.19.0-alt2.rc1 | 0.25.1-alt1 | ALT-PU-2018-2326-1 | 212986 | Fixed |
opensc | p10 | 0.19.0-alt2.rc1 | 0.25.1-alt1 | ALT-PU-2018-2326-1 | 212986 | Fixed |
opensc | p9 | 0.19.0-alt2.rc1 | 0.21.0-alt1 | ALT-PU-2018-2326-1 | 212986 | Fixed |
opensc | p8 | 0.19.0-alt1.rc1.M80P.1 | 0.19.0-alt2.M80P.1 | ALT-PU-2018-2463-1 | 212985 | Fixed |
opensc | c10f1 | 0.19.0-alt2.rc1 | 0.24.0-alt1 | ALT-PU-2018-2326-1 | 212986 | Fixed |
opensc | c9f2 | 0.19.0-alt2.rc1 | 0.24.0-alt1 | ALT-PU-2018-2326-1 | 212986 | Fixed |
References to Advisories, Solutions, and Tools
Hyperlink | Resource |
---|---|
https://www.x41-dsec.de/lab/advisories/x41-2018-002-OpenSC/ |
|
https://github.com/OpenSC/OpenSC/releases/tag/0.19.0-rc1 |
|
https://github.com/OpenSC/OpenSC/commit/360e95d45ac4123255a4c796db96337f332160ad#diff-476b3b2a03c4eef331b4b0bfece4b063 |
|
[debian-lts-announce] 20190911 [SECURITY] [DLA 1916-1] opensc security update |