CVE-2019-15946Improper Restriction of Operations within the Bounds of a Memory Buffer in Project Opensc

Severity
6.4MEDIUMNVD
EPSS
0.0%
top 84.91%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 5
Latest updateJun 8

Description

OpenSC before 0.20.0-rc1 has an out-of-bounds access of an ASN.1 Octet string in asn1_decode_entry in libopensc/asn1.c.

CVSS vector

CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 0.5 | Impact: 5.9

Affected Packages3 packages

Debianopensc_project/opensc< 0.20.0-1+3
Ubuntuopensc_project/opensc< 0.15.0-1ubuntu1+esm1+2

Also affects: Debian Linux 8.0, 9.0, Fedora 31

Patches

🔴Vulnerability Details

4
OSV
opensc vulnerabilities2022-06-08
GHSA
GHSA-mqh2-9c27-h9wq: OpenSC before 02022-05-24
CVEList
CVE-2019-15946: OpenSC before 02019-09-05
OSV
CVE-2019-15946: OpenSC before 02019-09-05

📋Vendor Advisories

3
Ubuntu
OpenSC vulnerabilities2022-06-08
Red Hat
opensc: Out-of-bounds access of an ASN.1 Octet string in asn1_decode_entry in libopensc/asn1.c2019-09-06
Debian
CVE-2019-15946: opensc - OpenSC before 0.20.0-rc1 has an out-of-bounds access of an ASN.1 Octet string in...2019

💬Community

3
Bugzilla
CVE-2019-15946 opensc: Out-of-bounds access of an ASN.1 Octet string in asn1_decode_entry in libopensc/asn1.c2019-10-24
Bugzilla
CVE-2019-15946 opensc: Out-of-bounds access of an ASN.1 Octet string in asn1_decode_entry in libopensc/asn1.c [epel-6]2019-10-24
Bugzilla
CVE-2019-15946 opensc: Out-of-bounds access of an ASN.1 Octet string in asn1_decode_entry in libopensc/asn1.c [fedora-all]2019-10-24
CVE-2019-15946 — Opensc Project Opensc vulnerability | cvebase