Memory leak in OpenSC - CVE-2019-6502

 

Memory leak in OpenSC - CVE-2019-6502

Published: January 24, 2019 / Updated: December 30, 2019


Vulnerability identifier: #VU17200
CSH Severity: Low
CVSS v4: 2.4 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-6502
CWE-ID: CWE-401
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to perform DoS attack on the target system.

The vulnerability exists due memory leak in sc_context_create in ctx.c in libopensc. A local user can trigger memory leak and perform denial of service attack.


Affected software

OpenSC
Arch Linux
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Linux Enterprise Micro
openSUSE Leap Micro
SUSE Enterprise Storage
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Module for Basesystem
SUSE Linux Enterprise Desktop
openSUSE Leap
opensc (Alpine package)
opensc
opensc-debuginfo
opensc-debugsource
opensc-32bit
opensc-32bit-debuginfo

How to mitigate CVE-2019-6502

Install update from vendor's website.

OpenSC - update to 0.20.0
opensc (Alpine package) - update to 0.20.0-r0
opensc - addressed in versions 0.18.0-150000.3.23.1, 0.19.0-150100.3.19.1
opensc-debuginfo - addressed in versions 0.18.0-150000.3.23.1, 0.19.0-150100.3.19.1
opensc-debugsource - addressed in versions 0.18.0-150000.3.23.1, 0.19.0-150100.3.19.1
opensc-32bit - update to 0.19.0-150100.3.19.1
opensc-32bit-debuginfo - update to 0.19.0-150100.3.19.1

External References

Related Security Bulletins