Several buffer overflows when handling responses from a Gemsafe V1 Smartcard in gemsafe_get_cert_len in libopensc/pkcs15-gemsafeV1.c in OpenSC before 0.19.0-rc1 could be used by attackers able to supply crafted smartcards to cause a denial of service (application crash) or possibly have unspecified other impact.
CVSS Details
- CVSS 3.1 Base Score: 6.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade opensc | Aug 22, 2024 | Sep 3, 2018 |
| Amazon Linux Ami 2 | — | Upgrade opensc-debuginfoUpgrade opensc | Apr 27, 2020 | Sep 3, 2018 |
| Centos_linux | — | Upgrade openscUpgrade opensc-debuginfo | Aug 28, 2019 | Sep 3, 2018 |
| Debian | — | Upgrade opensc | Sep 13, 2019 | Sep 3, 2018 |
| Huawei Euleros 2_0_sp3 | — | Upgrade opensc | Apr 16, 2020 | Sep 3, 2018 |
| Oracle_linux | — | Upgrade opensc | Jul 21, 2020 | Sep 12, 2018 |
| Redhat_linux | — | Upgrade opensc-debuginfoUpgrade opensc | Aug 7, 2019 | Sep 3, 2018 |
| Suse | — | Upgrade libopensc2Upgrade libopensc2-32bitUpgrade opensc-develUpgrade opensc-32bitUpgrade opensc-x86Upgrade openscUpgrade libopensc2-x86 | Nov 6, 2018 | Sep 3, 2018 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | Sep 3, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub