CVE-2021-42780: Medium severity suse opensc vulnerability
A use after return issue was found in Opensc before version 0.22.0 in insertpin function that could potentially crash programs using the library.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is CVE-2021-42780?
CVE-2021-42780 is a vulnerability in Opensc before version 0.22.0 that could potentially crash programs using the library.
How severe is CVE-2021-42780?
CVE-2021-42780 has a severity score of 5.3, which is considered medium.
What is the affected software for CVE-2021-42780?
The affected software includes Opensc before version 0.22.0, Fedora 33, Red Hat Enterprise Linux 7.0, and the redhat/opensc package.
How can I fix CVE-2021-42780?
To fix CVE-2021-42780, you should update Opensc to version 0.22.0 or later.
Where can I find more information about CVE-2021-42780?
You can find more information about CVE-2021-42780 in the referenced links: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=28383, https://bugzilla.redhat.com/show_bug.cgi?id=2016139, and https://github.com/OpenSC/OpenSC/commit/5df913b7.