CVE-2018-16426: Medium severity suse opensc vulnerability
Endless recursion when handling responses from an IAS-ECC card in iaseccselectfile in libopensc/card-iasecc.c in OpenSC before 0.19.0-rc1 could be used by attackers able to supply crafted smartcards to hang or crash the opensc library using programs.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2018-16426?
CVE-2018-16426 is a vulnerability that makes OpenSC before 0.19.0-rc1 susceptible to endless recursion when handling responses from an IAS-ECC card in iasecc_select_file in libopensc/card-iasecc.c, allowing attackers to hang or crash the opensc library using crafted smartcards.
What is the severity of CVE-2018-16426?
CVE-2018-16426 has a severity level of 4.3, which is considered medium.
What software is affected by CVE-2018-16426?
The OpenSC project's opensc version up to and including 0.18.0 is affected by CVE-2018-16426, as well as Red Hat's opensc version up to but excluding 0.19.0.
How can CVE-2018-16426 be fixed?
To fix CVE-2018-16426, users should update to OpenSC 0.19.0-rc1 or later version.
What is the Common Weakness Enumeration (CWE) ID for CVE-2018-16426?
The Common Weakness Enumeration (CWE) ID for CVE-2018-16426 is 674.