Double Free Vulnerability in OpenSC Software by OpenSC
CVE-2019-20792

6.8MEDIUM

Key Information:

Status
Vendor
CVE Published:
29 April 2020

What is CVE-2019-20792?

A double free vulnerability exists in the OpenSC library prior to version 0.20.0, specifically due to a lack of uniqueness checks in the coolkey_add_object function within libopensc/card-coolkey.c. This flaw allows an attacker to potentially manipulate memory, which may result in unexpected behaviors, data corruption, or security breaches.

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.