Red Hat Bugzilla – Bug 1628026
CVE-2018-16420 opensc: Buffer overflows handling responses from ePass 2003 Cards in card-epass2003.c:decrypt_response()
Last modified: 2018-09-18 04:09:31 EDT
Several buffer overflows when handling responses from an ePass 2003 Card in decrypt_response in libopensc/card-epass2003.c in OpenSC before 0.19.0-rc1 could be used by attackers able to supply crafted smartcards to cause a denial of service (application crash) or possibly have unspecified other impact. External References: https://www.x41-dsec.de/lab/advisories/x41-2018-002-OpenSC/ Upstream Patch: https://github.com/OpenSC/OpenSC/commit/360e95d45ac4123255a4c796db96337f332160ad#diff-b36536074d13447fbbec061e0e64d15d
Created opensc tracking bugs for this issue: Affects: fedora-all [bug 1628028]