Out-of-Bounds Access in OpenSC Software
CVE-2019-15946

6.4MEDIUM

Key Information:

Status
Vendor
CVE Published:
5 September 2019

What is CVE-2019-15946?

The vulnerability in OpenSC prior to version 0.20.0-rc1 involves out-of-bounds access of an ASN.1 Octet string during the processing of ASN.1 data structures, particularly in the 'asn1_decode_entry' function within the source file 'libopensc/asn1.c'. This flaw may allow attackers to exploit the vulnerability in various ways, leading to potential unauthorized access or manipulation of sensitive data.

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Physical
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.