Vulnerability CVE-2018-16418: Information
Description
A buffer overflow when handling string concatenation in util_acl_to_str in tools/util.c in OpenSC before 0.19.0-rc1 could be used by attackers able to supply crafted smartcards to cause a denial of service (application crash) or possibly have unspecified other impact.
Severity: MEDIUM (6.6) Vector: CVSS:3.0/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Fixed packages
Package name | Branch | Fixed in version | Version from repository | Errata ID | Task # | State |
---|---|---|---|---|---|---|
opensc | sisyphus | 0.19.0-alt2.rc1 | 0.25.1-alt1 | ALT-PU-2018-2326-1 | 212986 | Fixed |
opensc | p10 | 0.19.0-alt2.rc1 | 0.25.1-alt1 | ALT-PU-2018-2326-1 | 212986 | Fixed |
opensc | p9 | 0.19.0-alt2.rc1 | 0.21.0-alt1 | ALT-PU-2018-2326-1 | 212986 | Fixed |
opensc | p8 | 0.19.0-alt1.rc1.M80P.1 | 0.19.0-alt2.M80P.1 | ALT-PU-2018-2463-1 | 212985 | Fixed |
opensc | c10f1 | 0.19.0-alt2.rc1 | 0.24.0-alt1 | ALT-PU-2018-2326-1 | 212986 | Fixed |
opensc | c9f2 | 0.19.0-alt2.rc1 | 0.24.0-alt1 | ALT-PU-2018-2326-1 | 212986 | Fixed |
References to Advisories, Solutions, and Tools
Hyperlink | Resource |
---|---|
https://www.x41-dsec.de/lab/advisories/x41-2018-002-OpenSC/ |
|
https://github.com/OpenSC/OpenSC/releases/tag/0.19.0-rc1 |
|
https://github.com/OpenSC/OpenSC/commit/360e95d45ac4123255a4c796db96337f332160ad#diff-628c8445c4e7ae92bbc4be08ba11a4c3 |
|
RHSA-2019:2154 | |
[debian-lts-announce] 20190911 [SECURITY] [DLA 1916-1] opensc security update |