CVE-2018-16418: Buffer Overflow
A buffer overflow when handling string concatenation in utilacltostr in tools/util.c in OpenSC before 0.19.0-rc1 could be used by attackers able to supply crafted smartcards to cause a denial of service (application crash) or possibly have unspecified other impact.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2018-16418?
The severity of CVE-2018-16418 is medium with a CVSS score of 6.6.
How does CVE-2018-16418 impact the affected software?
CVE-2018-16418 could be used by attackers to cause a denial of service (application crash) or potentially have unspecified other impacts.
Which software versions are affected by CVE-2018-16418?
Versions up to and including 0.18.0 of OpenSC Project OpenSC and versions up to but not including 0.19.0 of Red Hat OpenSC are affected by CVE-2018-16418.
How can I fix CVE-2018-16418?
To fix CVE-2018-16418, upgrade to version 0.19.0 or later of OpenSC.
Where can I find more information about CVE-2018-16418?
More information about CVE-2018-16418 can be found in the following references: [Red Hat Advisory](https://access.redhat.com/errata/RHSA-2019:2154), [OpenSC Commit](https://github.com/OpenSC/OpenSC/commit/360e95d45ac4123255a4c796db96337f332160ad#diff-628c8445c4e7ae92bbc4be08ba11a4c3), [OpenSC Release](https://github.com/OpenSC/OpenSC/releases/tag/0.19.0-rc1).