Double-free error in OpenSC - CVE-2018-16423
Published: December 27, 2018
Vulnerability details
The vulnerability allows a remote attacker to cause DoS condition on the target system.
The vulnerability exists due to double-free error when handling responses from a smartcard in sc_file_set_sec_attr in libopensc/sc.c. A remote unauthenticated attacker can supply specially crafted smartcards, trigger memory corruption and cause the application to crash.
Affected software
opensc (Alpine package)
opensc
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for Scientific Computing
Opensuse
Fedora
How to mitigate CVE-2018-16423
opensc (Alpine package) - update to 0.19.0-r0
opensc - addressed in versions 0.19.0-1.fc28, 0.19.0-1.fc29