CVE-2018-16427Out-of-bounds Read in Project Opensc

Severity
4.3MEDIUMNVD
EPSS
0.2%
top 60.53%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 4
Latest updateMay 14

Description

Various out of bounds reads when handling responses in OpenSC before 0.19.0-rc1 could be used by attackers able to supply crafted smartcards to potentially crash the opensc library using programs.

CVSS vector

CVSS:3.0/AV:P/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 0.7 | Impact: 3.6

Affected Packages2 packages

Debianopensc_project/opensc< 0.19.0~rc1-1+3

Patches

🔴Vulnerability Details

3
GHSA
GHSA-35jr-36cj-2w6g: Various out of bounds reads when handling responses in OpenSC before 02022-05-14
OSV
CVE-2018-16427: Various out of bounds reads when handling responses in OpenSC before 02018-09-04
CVEList
CVE-2018-16427: Various out of bounds reads when handling responses in OpenSC before 02018-09-04

📋Vendor Advisories

2
Red Hat
opensc: Out of bounds reads handling responses from smartcards2018-09-12
Debian
CVE-2018-16427: opensc - Various out of bounds reads when handling responses in OpenSC before 0.19.0-rc1 ...2018

💬Community

2
Bugzilla
CVE-2018-16427 opensc: Out of bounds reads handling responses from smartcards2018-09-12
Bugzilla
CVE-2018-16427 opensc: Out of bounds reads handling responses from smartcards [fedora-all]2018-09-12
CVE-2018-16427 — Out-of-bounds Read in Project Opensc | cvebase