Double Free in OpenSC - CVE-2019-20792
Published: April 29, 2020 / Updated: August 8, 2020
Vulnerability identifier: #VU34415
CSH Severity: Medium
CVSS v4: 7 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-20792
CWE-ID: CWE-415
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local non-authenticated attacker to execute arbitrary code.
OpenSC before 0.20.0 has a double free in coolkey_free_private_data because coolkey_add_object in libopensc/card-coolkey.c lacks a uniqueness check.
Affected software
OpenSC
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server
SUSE Linux Enterprise Module for Basesystem
SUSE Linux Enterprise Server for SAP
opensc
opensc-debuginfo
opensc-debugsource
opensc (Red Hat package)
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server
SUSE Linux Enterprise Module for Basesystem
SUSE Linux Enterprise Server for SAP
opensc
opensc-debuginfo
opensc-debugsource
opensc (Red Hat package)
How to mitigate CVE-2019-20792
Install update from vendor's website.
OpenSC - update to 0.20.0
opensc - addressed in versions 0.18.0-150000.3.23.1, 0.19.0-3.7.1
opensc-debuginfo - addressed in versions 0.18.0-150000.3.23.1, 0.19.0-3.7.1
opensc-debugsource - addressed in versions 0.18.0-150000.3.23.1, 0.19.0-3.7.1
opensc (Red Hat package) - update to 0.20.0-2.el8
opensc - addressed in versions 0.18.0-150000.3.23.1, 0.19.0-3.7.1
opensc-debuginfo - addressed in versions 0.18.0-150000.3.23.1, 0.19.0-3.7.1
opensc-debugsource - addressed in versions 0.18.0-150000.3.23.1, 0.19.0-3.7.1
opensc (Red Hat package) - update to 0.20.0-2.el8