Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-20792

Опубликовано: 29 апр. 2020
Источник: debian

Описание

OpenSC before 0.20.0 has a double free in coolkey_free_private_data because coolkey_add_object in libopensc/card-coolkey.c lacks a uniqueness check.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
openscfixed0.20.0-1package
openscfixed0.19.0-1+deb10u1busterpackage
openscnot-affectedstretchpackage
openscpostponedjessiepackage

Примечания

  • https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=19208

  • https://github.com/OpenSC/OpenSC/commit/c246f6f69a749d4f68626b40795a4f69168008f4

Связанные уязвимости

CVSS3: 6.8
ubuntu
почти 6 лет назад

OpenSC before 0.20.0 has a double free in coolkey_free_private_data because coolkey_add_object in libopensc/card-coolkey.c lacks a uniqueness check.

CVSS3: 6.4
redhat
около 6 лет назад

OpenSC before 0.20.0 has a double free in coolkey_free_private_data because coolkey_add_object in libopensc/card-coolkey.c lacks a uniqueness check.

CVSS3: 6.8
nvd
почти 6 лет назад

OpenSC before 0.20.0 has a double free in coolkey_free_private_data because coolkey_add_object in libopensc/card-coolkey.c lacks a uniqueness check.

github
больше 3 лет назад

OpenSC before 0.20.0 has a double free in coolkey_free_private_data because coolkey_add_object in libopensc/card-coolkey.c lacks a uniqueness check.

oracle-oval
около 5 лет назад

ELSA-2020-4483: opensc security, bug fix, and enhancement update (MODERATE)