VulnerabilityModified
CVE-2021-42782
Stack buffer overflow issues were found in Opensc before version 0.22.0 in various places that could potentially crash programs using the library.
MEDIUM 5.3EPSS 2.78%
Does this matter?
Lower severity and a low EPSS score (2.78%). Track it; it rarely justifies an emergency change on its own.
Description
Stack buffer overflow issues were found in Opensc before version 0.22.0 in various places that could potentially crash programs using the library.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
- EPSS
- 2.78% probability · 86th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119, CWE-787
- Affected
- opensc project/opensc · fedoraproject/fedora
- Source
- secalert@redhat.com
References
- https://bugzilla.redhat.com/show_bug.cgi?id=2016448Issue Tracking, Mailing List, Patch, Third Party Advisory
- https://github.com/OpenSC/OpenSC/commit/1252aca9Patch, Third Party Advisory
- https://github.com/OpenSC/OpenSC/commit/456ac566Patch, Third Party Advisory
- https://github.com/OpenSC/OpenSC/commit/7114fb71Patch, Third Party Advisory
- https://github.com/OpenSC/OpenSC/commit/78cdab94Patch, Third Party Advisory
- https://github.com/OpenSC/OpenSC/commit/ae1cf0bePatch, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2023/06/msg00025.html
- https://security.gentoo.org/glsa/202209-03Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2016448Issue Tracking, Mailing List, Patch, Third Party Advisory
- https://github.com/OpenSC/OpenSC/commit/1252aca9Patch, Third Party Advisory
- https://github.com/OpenSC/OpenSC/commit/456ac566Patch, Third Party Advisory
- https://github.com/OpenSC/OpenSC/commit/7114fb71Patch, Third Party Advisory
- https://github.com/OpenSC/OpenSC/commit/78cdab94Patch, Third Party Advisory
- https://github.com/OpenSC/OpenSC/commit/ae1cf0bePatch, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2023/06/msg00025.html
- https://lists.debian.org/debian-lts-announce/2024/12/msg00026.html
- https://security.gentoo.org/glsa/202209-03Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.