Out-of-bounds read in OpenSC - CVE-2018-16427
Published: December 27, 2018
Vulnerability identifier: #VU16739
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-16427
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to cause DoS condition on the target system.
The vulnerability exists due to out-of-bounds read when handling responses. A remote unauthenticated attacker can supply specially crafted smartcards to crash the opensc library using programs.
Affected software
OpenSC
opensc (Alpine package)
opensc
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for Scientific Computing
Opensuse
Fedora
opensc (Alpine package)
opensc
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for Scientific Computing
Opensuse
Fedora
How to mitigate CVE-2018-16427
Update to version 0.19.0-rc1.
OpenSC - update to 0.19.0 rc1
opensc (Alpine package) - update to 0.19.0-r0
opensc - addressed in versions 0.19.0-1.fc28, 0.19.0-1.fc29
opensc (Alpine package) - update to 0.19.0-r0
opensc - addressed in versions 0.19.0-1.fc28, 0.19.0-1.fc29