Double Free in OpenSC - CVE-2019-20792

 

Double Free in OpenSC - CVE-2019-20792

Published: April 29, 2020 / Updated: August 8, 2020


Vulnerability identifier: #VU34415
CSH Severity: Medium
CVSS v4: 7 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-20792
CWE-ID: CWE-415
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local non-authenticated attacker to execute arbitrary code.

OpenSC before 0.20.0 has a double free in coolkey_free_private_data because coolkey_add_object in libopensc/card-coolkey.c lacks a uniqueness check.


Affected software

OpenSC
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server
SUSE Linux Enterprise Module for Basesystem
SUSE Linux Enterprise Server for SAP
opensc
opensc-debuginfo
opensc-debugsource
opensc (Red Hat package)

How to mitigate CVE-2019-20792

Install update from vendor's website.

OpenSC - update to 0.20.0
opensc - addressed in versions 0.18.0-150000.3.23.1, 0.19.0-3.7.1
opensc-debuginfo - addressed in versions 0.18.0-150000.3.23.1, 0.19.0-3.7.1
opensc-debugsource - addressed in versions 0.18.0-150000.3.23.1, 0.19.0-3.7.1
opensc (Red Hat package) - update to 0.20.0-2.el8

External References

Related Security Bulletins