QID 356142

Date Published: 2023-09-25

QID 356142: Amazon Linux Security Advisory for opensc : ALAS2-2023-2262

Opensc before 0.20.0-rc1 has an out-of-bounds access of an asn.1 bitstring in decode_bit_string in libopensc/asn1.c. (
( CVE-2019-15945) opensc before 0.20.0-rc1 has an out-of-bounds access of an asn.1 octet string in asn1_decode_entry in libopensc/asn1.c. (
( CVE-2019-15946) an issue was discovered in opensc through 0.19.0 and 0.20.x through 0.20.0-rc3.
Libopensc/card-setcos.c has an incorrect read operation during parsing of a setcos file attribute. (
( CVE-2019-19479) opensc before 0.20.0 has a double free in coolkey_free_private_data because coolkey_add_object in libopensc/card-coolkey.c lacks a uniqueness check. (
( CVE-2019-20792) the oberthur smart card software driver in opensc before 0.21.0-rc1 has a heap-based buffer overflow in sc_oberthur_read_file. (
( CVE-2020-26570) the gemsafe gpk smart card software driver in opensc before 0.21.0-rc1 has a stack-based buffer overflow in sc_pkcs15emu_gemsafegpk_init. (
( CVE-2020-26571) the tcos smart card software driver in opensc before 0.21.0-rc1 has a stack-based buffer overflow in tcos_decipher. (
( CVE-2020-26572)



Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.

Successful exploitation of this vulnerability could lead to a securitybreach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as High - 6.8 severity.
  • CVSS V2 rated as Medium - 4.6 severity.
  • Solution
    Please refer to Amazon advisory: ALAS2-2023-2262 for affected packages and patching details, or update with your package manager.
    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    ALAS2-2023-2262 amazon linux 2 URL Logo alas.aws.amazon.com/AL2/ALAS-2023-2262.html