CVE-2019-15946: Buffer Overflow
Published Sep 5, 2019
·Updated
OpenSC before 0.20.0-rc1 has an out-of-bounds access of an ASN.1 Octet string in asn1decodeentry in libopensc/asn1.c.
Affected Software
4 affected components
Opensc Project Opensc<=0.19.0
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Fedoraproject Fedora=31
Remediation
Patch Available
Event History
Sep 5, 2019
CVE Published
via MITRE·04:07 PM
Data Sourced
via MITRE·04:07 PM
Description
Frequently Asked Questions
1
What is CVE-2019-15946?
CVE-2019-15946 is a vulnerability in OpenSC before 0.20.0-rc1 that allows an out-of-bounds access of an ASN.1 Octet string.
2
How severe is CVE-2019-15946?
CVE-2019-15946 has a severity value of 6.4, which is considered medium.
3
What is the affected software?
The affected software includes OpenSC versions up to and including 0.19.0, Debian Linux 8.0 and 9.0, and Fedora 31.
4
How can I fix CVE-2019-15946?
To fix CVE-2019-15946, update to OpenSC version 0.20.0-rc1 or later.
5
Where can I find more information about CVE-2019-15946?
You can find more information about CVE-2019-15946 on the Openwall OSS Security mailing list and the OpenSC GitHub page.