Product:

Opensc

(Opensc_project)
Repositories https://github.com/OpenSC/OpenSC
#Vulnerabilities 36
Date Id Summary Products Score Patch Annotated
2020-10-06 CVE-2020-26570 The Oberthur smart card software driver in OpenSC before 0.21.0-rc1 has a heap-based buffer overflow in sc_oberthur_read_file. Debian_linux, Fedora, Opensc 5.5
2020-10-06 CVE-2020-26571 The gemsafe GPK smart card software driver in OpenSC before 0.21.0-rc1 has a stack-based buffer overflow in sc_pkcs15emu_gemsafeGPK_init. Debian_linux, Fedora, Opensc 5.5
2020-10-06 CVE-2020-26572 The TCOS smart card software driver in OpenSC before 0.21.0-rc1 has a stack-based buffer overflow in tcos_decipher. Debian_linux, Fedora, Opensc 5.5
2023-06-01 CVE-2023-2977 A vulnerbility was found in OpenSC. This security flaw cause a buffer overrun vulnerability in pkcs15 cardos_have_verifyrc_package. The attacker can supply a smart card package with malformed ASN1 context. The cardos_have_verifyrc_package function scans the ASN1 buffer for 2 tags, where remaining length is wrongly caculated due to moved starting pointer. This leads to possible heap-based buffer oob read. In cases where ASAN is enabled while compiling this causes a crash. Further info leak or... Opensc, Enterprise_linux 7.1
2019-01-22 CVE-2019-6502 sc_context_create in ctx.c in libopensc in OpenSC 0.19.0 has a memory leak, as demonstrated by a call from eidenv. Opensc 7.5
2022-04-18 CVE-2021-42779 A heap use after free issue was found in Opensc before version 0.22.0 in sc_file_valid. Fedora, Opensc, Enterprise_linux 5.3
2022-04-18 CVE-2021-42780 A use after return issue was found in Opensc before version 0.22.0 in insert_pin function that could potentially crash programs using the library. Fedora, Opensc, Enterprise_linux 5.3
2022-04-18 CVE-2021-42781 Heap buffer overflow issues were found in Opensc before version 0.22.0 in pkcs15-oberthur.c that could potentially crash programs using the library. Fedora, Opensc, Enterprise_linux 5.3
2022-04-18 CVE-2021-42782 Stack buffer overflow issues were found in Opensc before version 0.22.0 in various places that could potentially crash programs using the library. Fedora, Opensc 5.3
2022-04-18 CVE-2021-42778 A heap double free issue was found in Opensc before version 0.22.0 in sc_pkcs15_free_tokeninfo. Fedora, Opensc, Enterprise_linux 5.3