CVE-2018-16419: Buffer Overflow
Several buffer overflows when handling responses from a Cryptoflex card in readpublickey in tools/cryptoflex-tool.c in OpenSC before 0.19.0-rc1 could be used by attackers able to supply crafted smartcards to cause a denial of service (application crash) or possibly have unspecified other impact.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2018-16419?
CVE-2018-16419 is a vulnerability that allows attackers to cause a denial of service or have unspecified other impact by supplying crafted smartcards.
What is the severity of CVE-2018-16419?
The severity of CVE-2018-16419 is medium with a CVSS score of 6.6.
How can the CVE-2018-16419 vulnerability be exploited?
The vulnerability can be exploited by attackers who are able to supply crafted smartcards.
What software is affected by CVE-2018-16419?
OpenSC versions up to and including 0.18.0 are affected, as well as Red Hat OpenSC versions up to but not including 0.19.0.
How can I fix CVE-2018-16419?
To fix CVE-2018-16419, update to OpenSC version 0.19.0 or higher.