Input Validation Flaw in OpenSC Affects SETCOS File Attribute Handling
CVE-2019-19479
5.5MEDIUM
What is CVE-2019-19479?
A significant input validation issue has been identified in OpenSC, affecting version 0.19.0 and versions 0.20.x up to 0.20.0-rc3. The flaw exists within the libopensc/card-setcos.c component, where an incorrect read operation occurs during the parsing of a SETCOS file attribute. This vulnerability could potentially allow for undesirable behaviors when handling SETCOS files, warranting immediate attention to mitigate associated risks.
