#VU16738 Endless recursion in OpenSC - CVE-2018-16426
Published: December 27, 2018
OpenSC
OpenSC
Description
The vulnerability allows a remote attacker to cause DoS condition on the target system.
The vulnerability exists due to endless recursion when handling responses from an IAS-ECC card in iasecc_select_file in libopensc/card-iasecc.c. A remote unauthenticated attacker can supply specially crafted smartcards to hang or crash the opensc library using programs.