CVE-2018-16425
Severity CVSS v4.0:
Pending analysis
Type:
CWE-415
Double Free
Publication date:
04/09/2018
Last modified:
11/09/2019
Description
A double free when handling responses from an HSM Card in sc_pkcs15emu_sc_hsm_init in libopensc/pkcs15-sc-hsm.c in OpenSC before 0.19.0-rc1 could be used by attackers able to supply crafted smartcards to cause a denial of service (application crash) or possibly have unspecified other impact.
Impact
Base Score 3.x
6.60
Severity 3.x
MEDIUM
Base Score 2.0
4.60
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:opensc_project:opensc:*:*:*:*:*:*:*:* | 0.18.0 (including) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://github.com/OpenSC/OpenSC/commit/360e95d45ac4123255a4c796db96337f332160ad#diff-d643a0fa169471dbf2912f4866dc49c5
- https://github.com/OpenSC/OpenSC/releases/tag/0.19.0-rc1
- https://lists.debian.org/debian-lts-announce/2019/09/msg00009.html
- https://www.x41-dsec.de/lab/advisories/x41-2018-002-OpenSC/



