Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-16426

Опубликовано: 12 сент. 2018
Источник: redhat
CVSS3: 2.4
EPSS Низкий

Описание

Endless recursion when handling responses from an IAS-ECC card in iasecc_select_file in libopensc/card-iasecc.c in OpenSC before 0.19.0-rc1 could be used by attackers able to supply crafted smartcards to hang or crash the opensc library using programs.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 8openscNot affected
Red Hat Enterprise Linux 7openscFixedRHSA-2019:215406.08.2019

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-120
https://bugzilla.redhat.com/show_bug.cgi?id=1628044opensc: Infinite recusrion handling responses from IAS-ECC cards in card-iasecc.c:iasecc_select_file()

EPSS

Процентиль: 45%
0.00592
Низкий

2.4 Low

CVSS3

Связанные уязвимости

CVSS3: 4.3
ubuntu
почти 8 лет назад

Endless recursion when handling responses from an IAS-ECC card in iasecc_select_file in libopensc/card-iasecc.c in OpenSC before 0.19.0-rc1 could be used by attackers able to supply crafted smartcards to hang or crash the opensc library using programs.

CVSS3: 4.3
nvd
почти 8 лет назад

Endless recursion when handling responses from an IAS-ECC card in iasecc_select_file in libopensc/card-iasecc.c in OpenSC before 0.19.0-rc1 could be used by attackers able to supply crafted smartcards to hang or crash the opensc library using programs.

CVSS3: 4.3
debian
почти 8 лет назад

Endless recursion when handling responses from an IAS-ECC card in iase ...

CVSS3: 4.3
github
около 4 лет назад

Endless recursion when handling responses from an IAS-ECC card in iasecc_select_file in libopensc/card-iasecc.c in OpenSC before 0.19.0-rc1 could be used by attackers able to supply crafted smartcards to hang or crash the opensc library using programs.

suse-cvrf
больше 7 лет назад

Security update for opensc

EPSS

Процентиль: 45%
0.00592
Низкий

2.4 Low

CVSS3