4.6
CVSSv2

CVE-2018-16391

Published: 03/09/2018 Updated: 06/08/2019
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
CVSS v3 Base Score: 6.8 | Impact Score: 5.9 | Exploitability Score: 0.9
VMScore: 409
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Several buffer overflows when handling responses from a Muscle Card in muscle_list_files in libopensc/card-muscle.c in OpenSC prior to 0.19.0-rc1 could be used by attackers able to supply crafted smartcards to cause a denial of service (application crash) or possibly have unspecified other impact.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

opensc project opensc

Vendor Advisories

Debian Bug report logs - #909444 Minor security issues, CVE-2018-{16391-16393,16418-16427} Package: opensc; Maintainer for opensc is Debian OpenSC Maintainers <pkg-opensc-maint@listsaliothdebianorg>; Source for opensc is src:opensc (PTS, buildd, popcon) Reported by: Eric Dorland <eric@debianorg> Date: Sun, 23 Sep ...
Several buffer overflows when handling responses from a Muscle Card in muscle_list_files in libopensc/card-musclec in OpenSC before 0190-rc1 could be used by attackers able to supply crafted smartcards to cause a denial of service (application crash) or possibly have unspecified other impact(CVE-2018-16391) Several buffer overflows when handlin ...
Several buffer overflows when handling responses from a Muscle Card in muscle_list_files in libopensc/card-musclec in OpenSC before 0190-rc1 could be used by attackers able to supply crafted smartcards to cause a denial of service (application crash) or possibly have unspecified other impact ...