CVE-2019-15946 — Improper Restriction of Operations within the Bounds of a Memory Buffer in Project Opensc
CWE-119 — Improper Restriction of Operations within the Bounds of a Memory Buffer11 documents8 sources
Severity
6.4MEDIUMNVD
EPSS
0.0%
top 84.91%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 5
Latest updateJun 8
Description
OpenSC before 0.20.0-rc1 has an out-of-bounds access of an ASN.1 Octet string in asn1_decode_entry in libopensc/asn1.c.
CVSS vector
CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 0.5 | Impact: 5.9
Affected Packages3 packages
Also affects: Debian Linux 8.0, 9.0, Fedora 31
Patches
🔴Vulnerability Details
4📋Vendor Advisories
3💬Community
3Bugzilla▶
CVE-2019-15946 opensc: Out-of-bounds access of an ASN.1 Octet string in asn1_decode_entry in libopensc/asn1.c↗2019-10-24
Bugzilla▶
CVE-2019-15946 opensc: Out-of-bounds access of an ASN.1 Octet string in asn1_decode_entry in libopensc/asn1.c [epel-6]↗2019-10-24
Bugzilla▶
CVE-2019-15946 opensc: Out-of-bounds access of an ASN.1 Octet string in asn1_decode_entry in libopensc/asn1.c [fedora-all]↗2019-10-24