Red Hat Bugzilla – Bug 1628044
CVE-2018-16426 opensc: Infinite recusrion handling responses from IAS-ECC cards in card-iasecc.c:iasecc_select_file()
Last modified: 2018-09-18 04:12:16 EDT
Endless recursion when handling responses from an IAS-ECC card in iasecc_select_file in libopensc/card-iasecc.c in OpenSC before 0.19.0-rc1 could be used by attackers able to supply crafted smartcards to hang or crash the opensc library using programs. External References: https://www.x41-dsec.de/lab/advisories/x41-2018-002-OpenSC/ Upstream Patch: https://github.com/OpenSC/OpenSC/commit/03628449b75a93787eb2359412a3980365dda49b#diff-f8c0128e14031ed9307d47f10f601b54
Created opensc tracking bugs for this issue: Affects: fedora-all [bug 1628048]