Several buffer overflows when handling responses from a CAC Card in cac_get_serial_nr_from_CUID in libopensc/card-cac.c in OpenSC before 0.19.0-rc1 could be used by attackers able to supply crafted smartcards to cause a denial of service (application crash) or possibly have unspecified other impact.
CVSS Details
- CVSS 3.1 Base Score: 6.6
- CVSS 3.0 Vector: (CVSS:3.0/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade opensc | Aug 22, 2024 | Sep 4, 2018 |
| Amazon Linux Ami 2 | — | Upgrade openscUpgrade opensc-debuginfo | Apr 27, 2020 | Sep 4, 2018 |
| Centos_linux | — | Upgrade openscUpgrade opensc-debuginfo | Aug 28, 2019 | Sep 4, 2018 |
| Debian | — | Upgrade opensc | Sep 13, 2019 | Sep 4, 2018 |
| Huawei Euleros 2_0_sp3 | — | Upgrade opensc | Apr 16, 2020 | Sep 4, 2018 |
| Oracle_linux | — | Upgrade opensc | Jul 21, 2020 | Sep 12, 2018 |
| Redhat_linux | — | Upgrade opensc-debuginfoUpgrade opensc | Aug 7, 2019 | Sep 4, 2018 |
| Suse | — | Upgrade openscUpgrade opensc-32bit | Nov 10, 2018 | Sep 3, 2018 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | Sep 4, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub