Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-16426

Опубликовано: 12 сент. 2018
Источник: redhat
CVSS3: 2.4
EPSS Низкий

Описание

Endless recursion when handling responses from an IAS-ECC card in iasecc_select_file in libopensc/card-iasecc.c in OpenSC before 0.19.0-rc1 could be used by attackers able to supply crafted smartcards to hang or crash the opensc library using programs.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 8openscNot affected
Red Hat Enterprise Linux 7openscFixedRHSA-2019:215406.08.2019

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-120
https://bugzilla.redhat.com/show_bug.cgi?id=1628044opensc: Infinite recusrion handling responses from IAS-ECC cards in card-iasecc.c:iasecc_select_file()

EPSS

Процентиль: 39%
0.00178
Низкий

2.4 Low

CVSS3

Связанные уязвимости

CVSS3: 4.3
ubuntu
больше 7 лет назад

Endless recursion when handling responses from an IAS-ECC card in iasecc_select_file in libopensc/card-iasecc.c in OpenSC before 0.19.0-rc1 could be used by attackers able to supply crafted smartcards to hang or crash the opensc library using programs.

CVSS3: 4.3
nvd
больше 7 лет назад

Endless recursion when handling responses from an IAS-ECC card in iasecc_select_file in libopensc/card-iasecc.c in OpenSC before 0.19.0-rc1 could be used by attackers able to supply crafted smartcards to hang or crash the opensc library using programs.

CVSS3: 4.3
debian
больше 7 лет назад

Endless recursion when handling responses from an IAS-ECC card in iase ...

CVSS3: 4.3
github
больше 3 лет назад

Endless recursion when handling responses from an IAS-ECC card in iasecc_select_file in libopensc/card-iasecc.c in OpenSC before 0.19.0-rc1 could be used by attackers able to supply crafted smartcards to hang or crash the opensc library using programs.

suse-cvrf
около 7 лет назад

Security update for opensc

EPSS

Процентиль: 39%
0.00178
Низкий

2.4 Low

CVSS3