Use-after-free in OpenSC - CVE-2019-19480
Published: December 30, 2019
Vulnerability details
The vulnerability allows a local user to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within the sc_pkcs15_decode_prkdf_entry() function in libopensc/pkcs15-prkey.c. A local user can pass specially crafted data to the application, trigger a use-after-free error and execute arbitrary code on the system.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
Affected software
Arch Linux
SUSE Linux Enterprise Module for Basesystem
Fedora
opensc (Alpine package)
opensc
opensc-debuginfo
opensc-debugsource
How to mitigate CVE-2019-19480
opensc (Alpine package) - update to 0.20.0-r0
opensc - update to 0.19.0-3.7.1
opensc-debuginfo - update to 0.19.0-3.7.1
opensc-debugsource - update to 0.19.0-3.7.1
opensc - update to 0.20.0-3.fc31