cbcvebase.

Debian Opensc vulnerabilities

51 known vulnerabilities affecting debian/opensc.

Total CVEs
51
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
HIGH3MEDIUM19LOW28UNKNOWN1

Vulnerabilities

Page 2 of 3
CVE-2019-20792P4LOWCVSS 6.8fixed in opensc 0.20.0-1 (bookworm)2019
CVE-2019-20792 [MEDIUM] CVE-2019-20792: opensc - OpenSC before 0.20.0 has a double free in coolkey_free_private_data because cool... OpenSC before 0.20.0 has a double free in coolkey_free_private_data because coolkey_add_object in libopensc/card-coolkey.c lacks a uniqueness check. Scope: local bookworm: resolved (fixed in 0.20.0-1) bullseye: resolved (fixed in 0.20.0-1) forky: resolved (fixed in 0.20.0-1) sid: resolved (fixed in 0.20.0-1) trixie: resolved (fixed in 0.20.0-1)
debian
CVE-2019-15945P4MEDIUMCVSS 6.4fixed in opensc 0.20.0-1 (bookworm)2019
CVE-2019-15945 [MEDIUM] CVE-2019-15945: opensc - OpenSC before 0.20.0-rc1 has an out-of-bounds access of an ASN.1 Bitstring in de... OpenSC before 0.20.0-rc1 has an out-of-bounds access of an ASN.1 Bitstring in decode_bit_string in libopensc/asn1.c. Scope: local bookworm: resolved (fixed in 0.20.0-1) bullseye: resolved (fixed in 0.20.0-1) forky: resolved (fixed in 0.20.0-1) sid: resolved (fixed in 0.20.0-1) trixie: resolved (fixed in 0.20.0-1)
debian
CVE-2019-15946P4MEDIUMCVSS 6.4fixed in opensc 0.20.0-1 (bookworm)2019
CVE-2019-15946 [MEDIUM] CVE-2019-15946: opensc - OpenSC before 0.20.0-rc1 has an out-of-bounds access of an ASN.1 Octet string in... OpenSC before 0.20.0-rc1 has an out-of-bounds access of an ASN.1 Octet string in asn1_decode_entry in libopensc/asn1.c. Scope: local bookworm: resolved (fixed in 0.20.0-1) bullseye: resolved (fixed in 0.20.0-1) forky: resolved (fixed in 0.20.0-1) sid: resolved (fixed in 0.20.0-1) trixie: resolved (fixed in 0.20.0-1)
debian
CVE-2019-19479P4MEDIUMCVSS 5.5fixed in opensc 0.20.0-1 (bookworm)2019
CVE-2019-19479 [MEDIUM] CVE-2019-19479: opensc - An issue was discovered in OpenSC through 0.19.0 and 0.20.x through 0.20.0-rc3. ... An issue was discovered in OpenSC through 0.19.0 and 0.20.x through 0.20.0-rc3. libopensc/card-setcos.c has an incorrect read operation during parsing of a SETCOS file attribute. Scope: local bookworm: resolved (fixed in 0.20.0-1) bullseye: resolved (fixed in 0.20.0-1) forky: resolved (fixed in 0.20.0-1) sid: resolved (fixed in 0.20.0-1) trixie: resolved (fixed in
debian
CVE-2020-26570P4MEDIUMCVSS 5.5fixed in opensc 0.21.0-1 (bookworm)2020
CVE-2020-26570 [MEDIUM] CVE-2020-26570: opensc - The Oberthur smart card software driver in OpenSC before 0.21.0-rc1 has a heap-b... The Oberthur smart card software driver in OpenSC before 0.21.0-rc1 has a heap-based buffer overflow in sc_oberthur_read_file. Scope: local bookworm: resolved (fixed in 0.21.0-1) bullseye: resolved (fixed in 0.21.0-1) forky: resolved (fixed in 0.21.0-1) sid: resolved (fixed in 0.21.0-1) trixie: resolved (fixed in 0.21.0-1)
debian
CVE-2018-16393P4LOWCVSS 6.8fixed in opensc 0.19.0~rc1-1 (bookworm)2018
CVE-2018-16393 [MEDIUM] CVE-2018-16393: opensc - Several buffer overflows when handling responses from a Gemsafe V1 Smartcard in ... Several buffer overflows when handling responses from a Gemsafe V1 Smartcard in gemsafe_get_cert_len in libopensc/pkcs15-gemsafeV1.c in OpenSC before 0.19.0-rc1 could be used by attackers able to supply crafted smartcards to cause a denial of service (application crash) or possibly have unspecified other impact. Scope: local bookworm: resolved (fixed in 0.19.0~rc1-
debian
CVE-2018-16421P4LOWCVSS 6.6fixed in opensc 0.19.0~rc1-1 (bookworm)2018
CVE-2018-16421 [MEDIUM] CVE-2018-16421: opensc - Several buffer overflows when handling responses from a CAC Card in cac_get_seri... Several buffer overflows when handling responses from a CAC Card in cac_get_serial_nr_from_CUID in libopensc/card-cac.c in OpenSC before 0.19.0-rc1 could be used by attackers able to supply crafted smartcards to cause a denial of service (application crash) or possibly have unspecified other impact. Scope: local bookworm: resolved (fixed in 0.19.0~rc1-1) bullseye:
debian
CVE-2025-13763P4UNKNOWNfixed in opensc 0.27.0~rc1-1 (forky)2025
CVE-2025-13763 CVE-2025-13763: opensc bookworm: open bullseye: open forky: resolved (fixed in 0.27.0~rc1-1) sid: resolved (fixed in 0.27.0~rc1-1) trixie: open
debian
CVE-2018-16391P4LOWCVSS 6.8fixed in opensc 0.19.0~rc1-1 (bookworm)2018
CVE-2018-16391 [MEDIUM] CVE-2018-16391: opensc - Several buffer overflows when handling responses from a Muscle Card in muscle_li... Several buffer overflows when handling responses from a Muscle Card in muscle_list_files in libopensc/card-muscle.c in OpenSC before 0.19.0-rc1 could be used by attackers able to supply crafted smartcards to cause a denial of service (application crash) or possibly have unspecified other impact. Scope: local bookworm: resolved (fixed in 0.19.0~rc1-1) bullseye: reso
debian
CVE-2018-16392P4LOWCVSS 6.8fixed in opensc 0.19.0~rc1-1 (bookworm)2018
CVE-2018-16392 [MEDIUM] CVE-2018-16392: opensc - Several buffer overflows when handling responses from a TCOS Card in tcos_select... Several buffer overflows when handling responses from a TCOS Card in tcos_select_file in libopensc/card-tcos.c in OpenSC before 0.19.0-rc1 could be used by attackers able to supply crafted smartcards to cause a denial of service (application crash) or possibly have unspecified other impact. Scope: local bookworm: resolved (fixed in 0.19.0~rc1-1) bullseye: resolved
debian
CVE-2018-16422P4LOWCVSS 6.6fixed in opensc 0.19.0~rc1-1 (bookworm)2018
CVE-2018-16422 [MEDIUM] CVE-2018-16422: opensc - A single byte buffer overflow when handling responses from an esteid Card in sc_... A single byte buffer overflow when handling responses from an esteid Card in sc_pkcs15emu_esteid_init in libopensc/pkcs15-esteid.c in OpenSC before 0.19.0-rc1 could be used by attackers able to supply crafted smartcards to cause a denial of service (application crash) or possibly have unspecified other impact. Scope: local bookworm: resolved (fixed in 0.19.0~rc1-1)
debian
CVE-2018-16420P4LOWCVSS 6.6fixed in opensc 0.19.0~rc1-1 (bookworm)2018
CVE-2018-16420 [MEDIUM] CVE-2018-16420: opensc - Several buffer overflows when handling responses from an ePass 2003 Card in decr... Several buffer overflows when handling responses from an ePass 2003 Card in decrypt_response in libopensc/card-epass2003.c in OpenSC before 0.19.0-rc1 could be used by attackers able to supply crafted smartcards to cause a denial of service (application crash) or possibly have unspecified other impact. Scope: local bookworm: resolved (fixed in 0.19.0~rc1-1) bullsey
debian
CVE-2018-16419P4LOWCVSS 6.6fixed in opensc 0.19.0~rc1-1 (bookworm)2018
CVE-2018-16419 [MEDIUM] CVE-2018-16419: opensc - Several buffer overflows when handling responses from a Cryptoflex card in read_... Several buffer overflows when handling responses from a Cryptoflex card in read_public_key in tools/cryptoflex-tool.c in OpenSC before 0.19.0-rc1 could be used by attackers able to supply crafted smartcards to cause a denial of service (application crash) or possibly have unspecified other impact. Scope: local bookworm: resolved (fixed in 0.19.0~rc1-1) bullseye: re
debian
CVE-2018-16425P4LOWCVSS 6.6fixed in opensc 0.19.0~rc1-1 (bookworm)2018
CVE-2018-16425 [MEDIUM] CVE-2018-16425: opensc - A double free when handling responses from an HSM Card in sc_pkcs15emu_sc_hsm_in... A double free when handling responses from an HSM Card in sc_pkcs15emu_sc_hsm_init in libopensc/pkcs15-sc-hsm.c in OpenSC before 0.19.0-rc1 could be used by attackers able to supply crafted smartcards to cause a denial of service (application crash) or possibly have unspecified other impact. Scope: local bookworm: resolved (fixed in 0.19.0~rc1-1) bullseye: resolved
debian
CVE-2018-16423P4LOWCVSS 6.6fixed in opensc 0.19.0~rc1-1 (bookworm)2018
CVE-2018-16423 [MEDIUM] CVE-2018-16423: opensc - A double free when handling responses from a smartcard in sc_file_set_sec_attr i... A double free when handling responses from a smartcard in sc_file_set_sec_attr in libopensc/sc.c in OpenSC before 0.19.0-rc1 could be used by attackers able to supply crafted smartcards to cause a denial of service (application crash) or possibly have unspecified other impact. Scope: local bookworm: resolved (fixed in 0.19.0~rc1-1) bullseye: resolved (fixed in 0.19
debian
CVE-2018-16424P4LOWCVSS 6.6fixed in opensc 0.19.0~rc1-1 (bookworm)2018
CVE-2018-16424 [MEDIUM] CVE-2018-16424: opensc - A double free when handling responses in read_file in tools/egk-tool.c (aka the ... A double free when handling responses in read_file in tools/egk-tool.c (aka the eGK card tool) in OpenSC before 0.19.0-rc1 could be used by attackers able to supply crafted smartcards to cause a denial of service (application crash) or possibly have unspecified other impact. Scope: local bookworm: resolved (fixed in 0.19.0~rc1-1) bullseye: resolved (fixed in 0.19.0
debian
CVE-2018-16418P4LOWCVSS 6.6fixed in opensc 0.19.0~rc1-1 (bookworm)2018
CVE-2018-16418 [MEDIUM] CVE-2018-16418: opensc - A buffer overflow when handling string concatenation in util_acl_to_str in tools... A buffer overflow when handling string concatenation in util_acl_to_str in tools/util.c in OpenSC before 0.19.0-rc1 could be used by attackers able to supply crafted smartcards to cause a denial of service (application crash) or possibly have unspecified other impact. Scope: local bookworm: resolved (fixed in 0.19.0~rc1-1) bullseye: resolved (fixed in 0.19.0~rc1-1)
debian
CVE-2024-45619P4MEDIUMCVSS 4.3fixed in opensc 0.23.0-0.3+deb12u2 (bookworm)2024
CVE-2024-45619 [MEDIUM] CVE-2024-45619: opensc - A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, a... A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. When buffers are partially filled with data, initialized parts of the buffer can be incorrectly accessed. Scope: local bookworm: resolved (fixed i
debian
CVE-2008-2235P4MEDIUMCVSS 4.9fixed in opensc 0.11.4-4 (bookworm)2008
CVE-2008-2235 [MEDIUM] CVE-2008-2235: opensc - OpenSC before 0.11.5 uses weak permissions (ADMIN file control information of 00... OpenSC before 0.11.5 uses weak permissions (ADMIN file control information of 00) for the 5015 directory on smart cards and USB crypto tokens running Siemens CardOS M4, which allows physically proximate attackers to change the PIN. Scope: local bookworm: resolved (fixed in 0.11.4-4) bullseye: resolved (fixed in 0.11.4-4) forky: resolved (fixed in 0.11.4-4) sid: resol
debian
CVE-2008-3972P4MEDIUMCVSS 4.9fixed in opensc 0.11.4-5 (bookworm)2008
CVE-2008-3972 [MEDIUM] CVE-2008-3972: opensc - pkcs15-tool in OpenSC before 0.11.6 does not apply security updates to a smart c... pkcs15-tool in OpenSC before 0.11.6 does not apply security updates to a smart card unless the card's label matches the "OpenSC" string, which might allow physically proximate attackers to exploit vulnerabilities that the card owner expected were patched, as demonstrated by exploitation of CVE-2008-2235. Scope: local bookworm: resolved (fixed in 0.11.4-5) bullseye: r
debian
Debian Opensc vulnerabilities | cvebase