Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-16424

Опубликовано: 12 сент. 2018
Источник: redhat
CVSS3: 4.3
EPSS Низкий

Описание

A double free when handling responses in read_file in tools/egk-tool.c (aka the eGK card tool) in OpenSC before 0.19.0-rc1 could be used by attackers able to supply crafted smartcards to cause a denial of service (application crash) or possibly have unspecified other impact.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7openscNot affected
Red Hat Enterprise Linux 8openscNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-120
https://bugzilla.redhat.com/show_bug.cgi?id=1628040opensc: Double free handling responses from smartcards in tools/egk-tool.c:read_file()

EPSS

Процентиль: 40%
0.00181
Низкий

4.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.6
ubuntu
почти 7 лет назад

A double free when handling responses in read_file in tools/egk-tool.c (aka the eGK card tool) in OpenSC before 0.19.0-rc1 could be used by attackers able to supply crafted smartcards to cause a denial of service (application crash) or possibly have unspecified other impact.

CVSS3: 6.6
nvd
почти 7 лет назад

A double free when handling responses in read_file in tools/egk-tool.c (aka the eGK card tool) in OpenSC before 0.19.0-rc1 could be used by attackers able to supply crafted smartcards to cause a denial of service (application crash) or possibly have unspecified other impact.

CVSS3: 6.6
debian
почти 7 лет назад

A double free when handling responses in read_file in tools/egk-tool.c ...

CVSS3: 6.6
github
больше 3 лет назад

A double free when handling responses in read_file in tools/egk-tool.c (aka the eGK card tool) in OpenSC before 0.19.0-rc1 could be used by attackers able to supply crafted smartcards to cause a denial of service (application crash) or possibly have unspecified other impact.

suse-cvrf
почти 7 лет назад

Security update for opensc

EPSS

Процентиль: 40%
0.00181
Низкий

4.3 Medium

CVSS3