Out-of-Bounds Access Vulnerability in OpenSC Software
CVE-2019-15945

6.4MEDIUM

Key Information:

Status
Vendor
CVE Published:
5 September 2019

What is CVE-2019-15945?

The vulnerability in OpenSC allows for out-of-bounds access of ASN.1 Bitstring data in the decode_bit_string function located in libopensc/asn1.c. This exposure could potentially allow an attacker to manipulate memory, leading to further security risks. It is crucial for users to update their OpenSC software to versions following 0.20.0-rc1 to mitigate these risks.

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Physical
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.