First published: Sun Dec 01 2019(Updated: )
An issue was discovered in OpenSC through 0.19.0 and 0.20.x through 0.20.0-rc3. libopensc/pkcs15-prkey.c has an incorrect free operation in sc_pkcs15_decode_prkdf_entry.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Opensc Project Opensc | <=0.19.0 | |
Opensc Project Opensc | =0.20.0-rc1 | |
Opensc Project Opensc | =0.20.0-rc2 | |
Opensc Project Opensc | =0.20.0-rc3 | |
Linux Linux kernel |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-19480 is a vulnerability discovered in OpenSC through version 0.19.0 and version 0.20.x through 0.20.0-rc3. It is caused by an incorrect free operation in the libopensc/pkcs15-prkey.c file.
The severity of CVE-2019-19480 is medium, with a CVSS score of 4.6.
OpenSC versions 0.19.0 and 0.20.x (up to and including 0.20.0-rc3) are affected by CVE-2019-19480.
To fix CVE-2019-19480, it is recommended to update to a version of OpenSC that is not affected by the vulnerability, such as version 0.20.1 or later.
You can find more information about CVE-2019-19480 on the following references: [link1], [link2], [link3].