Buffer overflow in OpenSC - CVE-2018-16393

 

Buffer overflow in OpenSC - CVE-2018-16393

Published: December 27, 2018


Vulnerability identifier: #VU16732
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-16393
CWE-ID: CWE-120
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause DoS condition on the target system.

The vulnerability exists due to boundary error when handling responses from a Gemsafe V1 Smartcard in gemsafe_get_cert_len in libopensc/pkcs15-gemsafeV1.c. A remote unauthenticated attacker can supply specially crafted smartcards, trigger memory corruption and cause the application to crash.


Affected software

OpenSC
opensc (Alpine package)
opensc
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for Scientific Computing
Opensuse
Fedora

How to mitigate CVE-2018-16393

Update to version 0.19.0-rc1.

OpenSC - update to 0.19.0 rc1
opensc (Alpine package) - update to 0.19.0-r0
opensc - addressed in versions 0.19.0-1.fc28, 0.19.0-1.fc29

External References

Related Security Bulletins