2.1
CVSSv2

CVE-2018-16426

Published: 04/09/2018 Updated: 03/10/2019
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
CVSS v3 Base Score: 4.3 | Impact Score: 3.6 | Exploitability Score: 0.7
VMScore: 187
Vector: AV:L/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

Endless recursion when handling responses from an IAS-ECC card in iasecc_select_file in libopensc/card-iasecc.c in OpenSC prior to 0.19.0-rc1 could be used by attackers able to supply crafted smartcards to hang or crash the opensc library using programs.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

opensc project opensc

Vendor Advisories

Debian Bug report logs - #909444 Minor security issues, CVE-2018-{16391-16393,16418-16427} Package: opensc; Maintainer for opensc is Debian OpenSC Maintainers <pkg-opensc-maint@listsaliothdebianorg>; Source for opensc is src:opensc (PTS, buildd, popcon) Reported by: Eric Dorland <eric@debianorg> Date: Sun, 23 Sep ...
Several buffer overflows when handling responses from a Muscle Card in muscle_list_files in libopensc/card-musclec in OpenSC before 0190-rc1 could be used by attackers able to supply crafted smartcards to cause a denial of service (application crash) or possibly have unspecified other impact(CVE-2018-16391) Several buffer overflows when handlin ...
Endless recursion when handling responses from an IAS-ECC card in iasecc_select_file in libopensc/card-iaseccc in OpenSC before 0190-rc1 could be used by attackers able to supply crafted smartcards to hang or crash the opensc library using programs ...