CVE-2019-16058
HIGHOpenSC pam_p11 0.2.0 and 0.3.0 - Buffer Overflow via Long Smart Card Signature
Title source: llmDescription
An issue was discovered in the pam_p11 component 0.2.0 and 0.3.0 for OpenSC. If a smart card creates a signature with a length longer than 256 bytes, this triggers a buffer overflow. This may be the case for RSA keys with 4096 bits depending on the signature scheme.
References (2)
Core 2
Core References
Patch, Third Party Advisory x_refsource_misc
https://github.com/OpenSC/pam_p11/commit/d150b60e1e14c261b113f55681419ad1dfa8a76c
Mailing List mailing-list
x_refsource_mlist
http://www.openwall.com/lists/oss-security/2019/09/12/1
Scores
CVSS v3
7.5
EPSS
0.0035
EPSS Percentile
58.1%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Details
CWE
CWE-119
Status
published
Products (2)
opensc_project/opensc
0.2.0
opensc_project/opensc
0.3.0
Published
Sep 06, 2019
Tracked Since
Feb 18, 2026