CVE-2020-26571: Buffer Overflow
Published Oct 6, 2020
·Updated
The gemsafe GPK smart card software driver in OpenSC before 0.21.0-rc1 has a stack-based buffer overflow in scpkcs15emugemsafeGPKinit.
Affected Software
3 affected components
Opensc Project Opensc<=0.20.0
Debian Debian Linux=9.0
Fedoraproject Fedora=33
Event History
Oct 6, 2020
CVE Published
via MITRE·01:04 AM
Data Sourced
via MITRE·01:04 AM
Description
Frequently Asked Questions
1
What is CVE-2020-26571?
CVE-2020-26571 refers to a stack-based buffer overflow vulnerability in the gemsafe GPK smart card software driver in OpenSC before 0.21.0-rc1.
2
What is the severity of CVE-2020-26571?
The severity of CVE-2020-26571 is medium with a CVSS score of 5.5.
3
Which software versions are affected by CVE-2020-26571?
The affected software versions are OpenSC before 0.21.0-rc1, Debian Linux 9.0, and Fedora 33.
4
How can I fix CVE-2020-26571?
To fix CVE-2020-26571, update to OpenSC version 0.21.0-rc1 or later.
5
What are the references for CVE-2020-26571?
The references for CVE-2020-26571 are: [1] http://www.openwall.com/lists/oss-security/2020/11/24/4, [2] https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=20612, [3] https://lists.debian.org/debian-lts-announce/2021/11/msg00027.html.