First published: Tue Sep 04 2018(Updated: )
A buffer overflow when handling string concatenation in util_acl_to_str in tools/util.c in OpenSC before 0.19.0-rc1 could be used by attackers able to supply crafted smartcards to cause a denial of service (application crash) or possibly have unspecified other impact.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Opensc Project Opensc | <=0.18.0 | |
redhat/opensc | <0.19.0 | 0.19.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-16418 is medium with a CVSS score of 6.6.
CVE-2018-16418 could be used by attackers to cause a denial of service (application crash) or potentially have unspecified other impacts.
Versions up to and including 0.18.0 of OpenSC Project OpenSC and versions up to but not including 0.19.0 of Red Hat OpenSC are affected by CVE-2018-16418.
To fix CVE-2018-16418, upgrade to version 0.19.0 or later of OpenSC.
More information about CVE-2018-16418 can be found in the following references: [Red Hat Advisory](https://access.redhat.com/errata/RHSA-2019:2154), [OpenSC Commit](https://github.com/OpenSC/OpenSC/commit/360e95d45ac4123255a4c796db96337f332160ad#diff-628c8445c4e7ae92bbc4be08ba11a4c3), [OpenSC Release](https://github.com/OpenSC/OpenSC/releases/tag/0.19.0-rc1).