Several buffer overflows when handling responses from a Gemsafe V1 Smartcard in gemsafe_get_cert_len in libopensc/pkcs15-gemsafeV1.c in OpenSC before 0.19.0-rc1 could be used by attackers able to supply crafted smartcards to cause a denial of service (application crash) or possibly have unspecified other impact.
CVSS Details
- CVSS 3.1 Base Score: 6.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade opensc | Aug 22, 2024 | Sep 3, 2018 |
| Amazon Linux Ami 2 | — | Upgrade opensc-debuginfoUpgrade opensc | Apr 27, 2020 | Sep 3, 2018 |
| Centos_linux | — | Upgrade opensc-debuginfoUpgrade opensc | Aug 28, 2019 | Sep 3, 2018 |
| Debian | — | Upgrade opensc | Sep 13, 2019 | Sep 3, 2018 |
| Huawei Euleros 2_0_sp3 | — | Upgrade opensc | Apr 16, 2020 | Sep 3, 2018 |
| Oracle_linux | — | Upgrade opensc | Jul 21, 2020 | Sep 12, 2018 |
| Redhat_linux | — | Upgrade openscUpgrade opensc-debuginfo | Aug 7, 2019 | Sep 3, 2018 |
| Suse | — | Upgrade libopensc2Upgrade libopensc2-32bitUpgrade opensc-develUpgrade openscUpgrade libopensc2-x86Upgrade opensc-32bitUpgrade opensc-x86 | Nov 6, 2018 | Sep 3, 2018 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | Sep 3, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub