CVE-2018-16420: Buffer Overflow
Published Sep 4, 2018
·Updated
Several buffer overflows when handling responses from an ePass 2003 Card in decryptresponse in libopensc/card-epass2003.c in OpenSC before 0.19.0-rc1 could be used by attackers able to supply crafted smartcards to cause a denial of service (application crash) or possibly have unspecified other impact.
Affected Software
2 affected componentsFixes available
redhat/opensc<0.19.0
0.19.0
Opensc Project Opensc<=0.18.0
Remediation
Patch Available
Event History
Sep 4, 2018
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2018-16420.
2
What is the severity of CVE-2018-16420?
The severity of CVE-2018-16420 is medium with a CVSS score of 6.6.
3
What is the affected software for CVE-2018-16420?
The affected software for CVE-2018-16420 is OpenSC versions up to and including 0.18.0.
4
How can an attacker exploit CVE-2018-16420?
An attacker can exploit CVE-2018-16420 by supplying crafted smartcards to the affected system.
5
How can I fix CVE-2018-16420?
To fix CVE-2018-16420, update to OpenSC version 0.19.0 or later.