Debian Opensc vulnerabilities
52 known vulnerabilities affecting debian/opensc.
Total CVEs
52
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
HIGH3MEDIUM19LOW29UNKNOWN1
Vulnerabilities
Page 2 of 3
CVE-2021-42781MEDIUMCVSS 5.3fixed in opensc 0.22.0-1 (bookworm)2021
CVE-2021-42781 [MEDIUM] CVE-2021-42781: opensc - Heap buffer overflow issues were found in Opensc before version 0.22.0 in pkcs15...
Heap buffer overflow issues were found in Opensc before version 0.22.0 in pkcs15-oberthur.c that could potentially crash programs using the library.
Scope: local
bookworm: resolved (fixed in 0.22.0-1)
bullseye: resolved (fixed in 0.21.0-1+deb11u1)
forky: resolved (fixed in 0.22.0-1)
sid: resolved (fixed in 0.22.0-1)
trixie: resolved (fixed in 0.22.0-1)
debian
CVE-2021-42780MEDIUMCVSS 5.3fixed in opensc 0.22.0-1 (bookworm)2021
CVE-2021-42780 [MEDIUM] CVE-2021-42780: opensc - A use after return issue was found in Opensc before version 0.22.0 in insert_pin...
A use after return issue was found in Opensc before version 0.22.0 in insert_pin function that could potentially crash programs using the library.
Scope: local
bookworm: resolved (fixed in 0.22.0-1)
bullseye: resolved (fixed in 0.21.0-1+deb11u1)
forky: resolved (fixed in 0.22.0-1)
sid: resolved (fixed in 0.22.0-1)
trixie: resolved (fixed in 0.22.0-1)
debian
CVE-2021-42782MEDIUMCVSS 5.3fixed in opensc 0.22.0-1 (bookworm)2021
CVE-2021-42782 [MEDIUM] CVE-2021-42782: opensc - Stack buffer overflow issues were found in Opensc before version 0.22.0 in vario...
Stack buffer overflow issues were found in Opensc before version 0.22.0 in various places that could potentially crash programs using the library.
Scope: local
bookworm: resolved (fixed in 0.22.0-1)
bullseye: resolved (fixed in 0.21.0-1+deb11u1)
forky: resolved (fixed in 0.22.0-1)
sid: resolved (fixed in 0.22.0-1)
trixie: resolved (fixed in 0.22.0-1)
debian
CVE-2021-42778MEDIUMCVSS 5.3fixed in opensc 0.22.0-1 (bookworm)2021
CVE-2021-42778 [MEDIUM] CVE-2021-42778: opensc - A heap double free issue was found in Opensc before version 0.22.0 in sc_pkcs15_...
A heap double free issue was found in Opensc before version 0.22.0 in sc_pkcs15_free_tokeninfo.
Scope: local
bookworm: resolved (fixed in 0.22.0-1)
bullseye: resolved (fixed in 0.21.0-1+deb11u1)
forky: resolved (fixed in 0.22.0-1)
sid: resolved (fixed in 0.22.0-1)
trixie: resolved (fixed in 0.22.0-1)
debian
CVE-2020-26572MEDIUMCVSS 5.5fixed in opensc 0.21.0-1 (bookworm)2020
CVE-2020-26572 [MEDIUM] CVE-2020-26572: opensc - The TCOS smart card software driver in OpenSC before 0.21.0-rc1 has a stack-base...
The TCOS smart card software driver in OpenSC before 0.21.0-rc1 has a stack-based buffer overflow in tcos_decipher.
Scope: local
bookworm: resolved (fixed in 0.21.0-1)
bullseye: resolved (fixed in 0.21.0-1)
forky: resolved (fixed in 0.21.0-1)
sid: resolved (fixed in 0.21.0-1)
trixie: resolved (fixed in 0.21.0-1)
debian
CVE-2020-26571MEDIUMCVSS 5.5fixed in opensc 0.21.0-1 (bookworm)2020
CVE-2020-26571 [MEDIUM] CVE-2020-26571: opensc - The gemsafe GPK smart card software driver in OpenSC before 0.21.0-rc1 has a sta...
The gemsafe GPK smart card software driver in OpenSC before 0.21.0-rc1 has a stack-based buffer overflow in sc_pkcs15emu_gemsafeGPK_init.
Scope: local
bookworm: resolved (fixed in 0.21.0-1)
bullseye: resolved (fixed in 0.21.0-1)
forky: resolved (fixed in 0.21.0-1)
sid: resolved (fixed in 0.21.0-1)
trixie: resolved (fixed in 0.21.0-1)
debian
CVE-2020-26570MEDIUMCVSS 5.5fixed in opensc 0.21.0-1 (bookworm)2020
CVE-2020-26570 [MEDIUM] CVE-2020-26570: opensc - The Oberthur smart card software driver in OpenSC before 0.21.0-rc1 has a heap-b...
The Oberthur smart card software driver in OpenSC before 0.21.0-rc1 has a heap-based buffer overflow in sc_oberthur_read_file.
Scope: local
bookworm: resolved (fixed in 0.21.0-1)
bullseye: resolved (fixed in 0.21.0-1)
forky: resolved (fixed in 0.21.0-1)
sid: resolved (fixed in 0.21.0-1)
trixie: resolved (fixed in 0.21.0-1)
debian
CVE-2019-15945MEDIUMCVSS 6.4fixed in opensc 0.20.0-1 (bookworm)2019
CVE-2019-15945 [MEDIUM] CVE-2019-15945: opensc - OpenSC before 0.20.0-rc1 has an out-of-bounds access of an ASN.1 Bitstring in de...
OpenSC before 0.20.0-rc1 has an out-of-bounds access of an ASN.1 Bitstring in decode_bit_string in libopensc/asn1.c.
Scope: local
bookworm: resolved (fixed in 0.20.0-1)
bullseye: resolved (fixed in 0.20.0-1)
forky: resolved (fixed in 0.20.0-1)
sid: resolved (fixed in 0.20.0-1)
trixie: resolved (fixed in 0.20.0-1)
debian
CVE-2019-19479MEDIUMCVSS 5.5fixed in opensc 0.20.0-1 (bookworm)2019
CVE-2019-19479 [MEDIUM] CVE-2019-19479: opensc - An issue was discovered in OpenSC through 0.19.0 and 0.20.x through 0.20.0-rc3. ...
An issue was discovered in OpenSC through 0.19.0 and 0.20.x through 0.20.0-rc3. libopensc/card-setcos.c has an incorrect read operation during parsing of a SETCOS file attribute.
Scope: local
bookworm: resolved (fixed in 0.20.0-1)
bullseye: resolved (fixed in 0.20.0-1)
forky: resolved (fixed in 0.20.0-1)
sid: resolved (fixed in 0.20.0-1)
trixie: resolved (fixed in
debian
CVE-2019-19481MEDIUMCVSS 4.6fixed in opensc 0.19.0~rc1-1 (bookworm)2019
CVE-2019-19481 [MEDIUM] CVE-2019-19481: opensc - An issue was discovered in OpenSC through 0.19.0 and 0.20.x through 0.20.0-rc3. ...
An issue was discovered in OpenSC through 0.19.0 and 0.20.x through 0.20.0-rc3. libopensc/card-cac1.c mishandles buffer limits for CAC certificates.
Scope: local
bookworm: resolved (fixed in 0.19.0~rc1-1)
bullseye: resolved (fixed in 0.19.0~rc1-1)
forky: resolved (fixed in 0.19.0~rc1-1)
sid: resolved (fixed in 0.19.0~rc1-1)
trixie: resolved (fixed in 0.19.0~rc1-1)
debian
CVE-2019-15946MEDIUMCVSS 6.4fixed in opensc 0.20.0-1 (bookworm)2019
CVE-2019-15946 [MEDIUM] CVE-2019-15946: opensc - OpenSC before 0.20.0-rc1 has an out-of-bounds access of an ASN.1 Octet string in...
OpenSC before 0.20.0-rc1 has an out-of-bounds access of an ASN.1 Octet string in asn1_decode_entry in libopensc/asn1.c.
Scope: local
bookworm: resolved (fixed in 0.20.0-1)
bullseye: resolved (fixed in 0.20.0-1)
forky: resolved (fixed in 0.20.0-1)
sid: resolved (fixed in 0.20.0-1)
trixie: resolved (fixed in 0.20.0-1)
debian
CVE-2019-6502LOWCVSS 7.5fixed in opensc 0.20.0-1 (bookworm)2019
CVE-2019-6502 [HIGH] CVE-2019-6502: opensc - sc_context_create in ctx.c in libopensc in OpenSC 0.19.0 has a memory leak, as d...
sc_context_create in ctx.c in libopensc in OpenSC 0.19.0 has a memory leak, as demonstrated by a call from eidenv.
Scope: local
bookworm: resolved (fixed in 0.20.0-1)
bullseye: resolved (fixed in 0.20.0-1)
forky: resolved (fixed in 0.20.0-1)
sid: resolved (fixed in 0.20.0-1)
trixie: resolved (fixed in 0.20.0-1)
debian
CVE-2019-20792LOWCVSS 6.8fixed in opensc 0.20.0-1 (bookworm)2019
CVE-2019-20792 [MEDIUM] CVE-2019-20792: opensc - OpenSC before 0.20.0 has a double free in coolkey_free_private_data because cool...
OpenSC before 0.20.0 has a double free in coolkey_free_private_data because coolkey_add_object in libopensc/card-coolkey.c lacks a uniqueness check.
Scope: local
bookworm: resolved (fixed in 0.20.0-1)
bullseye: resolved (fixed in 0.20.0-1)
forky: resolved (fixed in 0.20.0-1)
sid: resolved (fixed in 0.20.0-1)
trixie: resolved (fixed in 0.20.0-1)
debian
CVE-2019-19480LOWCVSS 4.62019
CVE-2019-19480 [MEDIUM] CVE-2019-19480: opensc - An issue was discovered in OpenSC through 0.19.0 and 0.20.x through 0.20.0-rc3. ...
An issue was discovered in OpenSC through 0.19.0 and 0.20.x through 0.20.0-rc3. libopensc/pkcs15-prkey.c has an incorrect free operation in sc_pkcs15_decode_prkdf_entry.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
debian
CVE-2018-16392LOWCVSS 6.8fixed in opensc 0.19.0~rc1-1 (bookworm)2018
CVE-2018-16392 [MEDIUM] CVE-2018-16392: opensc - Several buffer overflows when handling responses from a TCOS Card in tcos_select...
Several buffer overflows when handling responses from a TCOS Card in tcos_select_file in libopensc/card-tcos.c in OpenSC before 0.19.0-rc1 could be used by attackers able to supply crafted smartcards to cause a denial of service (application crash) or possibly have unspecified other impact.
Scope: local
bookworm: resolved (fixed in 0.19.0~rc1-1)
bullseye: resolved
debian
CVE-2018-16427LOWCVSS 4.3fixed in opensc 0.19.0~rc1-1 (bookworm)2018
CVE-2018-16427 [MEDIUM] CVE-2018-16427: opensc - Various out of bounds reads when handling responses in OpenSC before 0.19.0-rc1 ...
Various out of bounds reads when handling responses in OpenSC before 0.19.0-rc1 could be used by attackers able to supply crafted smartcards to potentially crash the opensc library using programs.
Scope: local
bookworm: resolved (fixed in 0.19.0~rc1-1)
bullseye: resolved (fixed in 0.19.0~rc1-1)
forky: resolved (fixed in 0.19.0~rc1-1)
sid: resolved (fixed in 0.19.0~
debian
CVE-2018-16425LOWCVSS 6.6fixed in opensc 0.19.0~rc1-1 (bookworm)2018
CVE-2018-16425 [MEDIUM] CVE-2018-16425: opensc - A double free when handling responses from an HSM Card in sc_pkcs15emu_sc_hsm_in...
A double free when handling responses from an HSM Card in sc_pkcs15emu_sc_hsm_init in libopensc/pkcs15-sc-hsm.c in OpenSC before 0.19.0-rc1 could be used by attackers able to supply crafted smartcards to cause a denial of service (application crash) or possibly have unspecified other impact.
Scope: local
bookworm: resolved (fixed in 0.19.0~rc1-1)
bullseye: resolved
debian
CVE-2018-16422LOWCVSS 6.6fixed in opensc 0.19.0~rc1-1 (bookworm)2018
CVE-2018-16422 [MEDIUM] CVE-2018-16422: opensc - A single byte buffer overflow when handling responses from an esteid Card in sc_...
A single byte buffer overflow when handling responses from an esteid Card in sc_pkcs15emu_esteid_init in libopensc/pkcs15-esteid.c in OpenSC before 0.19.0-rc1 could be used by attackers able to supply crafted smartcards to cause a denial of service (application crash) or possibly have unspecified other impact.
Scope: local
bookworm: resolved (fixed in 0.19.0~rc1-1)
debian
CVE-2018-16423LOWCVSS 6.6fixed in opensc 0.19.0~rc1-1 (bookworm)2018
CVE-2018-16423 [MEDIUM] CVE-2018-16423: opensc - A double free when handling responses from a smartcard in sc_file_set_sec_attr i...
A double free when handling responses from a smartcard in sc_file_set_sec_attr in libopensc/sc.c in OpenSC before 0.19.0-rc1 could be used by attackers able to supply crafted smartcards to cause a denial of service (application crash) or possibly have unspecified other impact.
Scope: local
bookworm: resolved (fixed in 0.19.0~rc1-1)
bullseye: resolved (fixed in 0.19
debian
CVE-2018-16424LOWCVSS 6.6fixed in opensc 0.19.0~rc1-1 (bookworm)2018
CVE-2018-16424 [MEDIUM] CVE-2018-16424: opensc - A double free when handling responses in read_file in tools/egk-tool.c (aka the ...
A double free when handling responses in read_file in tools/egk-tool.c (aka the eGK card tool) in OpenSC before 0.19.0-rc1 could be used by attackers able to supply crafted smartcards to cause a denial of service (application crash) or possibly have unspecified other impact.
Scope: local
bookworm: resolved (fixed in 0.19.0~rc1-1)
bullseye: resolved (fixed in 0.19.0
debian