Back to Database
Status published
Medium
CVE-2018-16427
Various out of bounds reads when handling responses in OpenSC...
Vulnerability Description
Various out of bounds reads when handling responses in OpenSC before 0.19.0-rc1 could be used by attackers able to supply crafted smartcards to potentially crash the opensc library using programs.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2018-16427
Credits & Attribution
No credits recorded in the NVD database.
References
- https://github.com/OpenSC/OpenSC/releases/tag/0.19.0-rc1
- https://github.com/OpenSC/OpenSC/pull/1447/commits/8fe377e93b4b56060e5bbfb6f3142ceaeca744fa
- https://www.x41-dsec.de/lab/advisories/x41-2018-002-OpenSC/
- https://access.redhat.com/errata/RHSA-2019:2154
- https://lists.debian.org/debian-lts-announce/2019/09/msg00009.html
More from opensc project
View All →CVE-2021-34193
Stack overflow vulnerability in OpenSC smart card middleware before 0.23...
High
7.5
CVE-2020-26572
The TCOS smart card software driver in OpenSC before 0.21.0-rc1...
Medium
5.5
CVE-2020-26571
The gemsafe GPK smart card software driver in OpenSC before...
Medium
5.5
CVE-2020-26570
The Oberthur smart card software driver in OpenSC before 0.21.0-rc1...
Medium
5.5
CVE-2019-6502
sc_context_create in ctx.c in libopensc in OpenSC 0.19.0 has a...
High
7.5
Affected Vendor
opensc project
View all reports →Affected Software
opensc
Vulnerable Versions:
0
Timeline
Official Publish:
September 4th, 2018
Last Modified:
August 5th, 2024
Added to House:
July 20th, 2026
CVSS Vectors
V3:
CVSS:3.0/AV:P/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.