{"affected":[{"ecosystem_specific":{"binaries":[{"opensc":"0.13.0-3.3.2"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Desktop 12 SP4","name":"opensc","purl":"pkg:rpm/suse/opensc&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP4"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"0.13.0-3.3.2"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"opensc":"0.13.0-3.3.2"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server 12 SP4","name":"opensc","purl":"pkg:rpm/suse/opensc&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP4"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"0.13.0-3.3.2"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"opensc":"0.13.0-3.3.2"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 12 SP4","name":"opensc","purl":"pkg:rpm/suse/opensc&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP4"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"0.13.0-3.3.2"}],"type":"ECOSYSTEM"}]}],"aliases":[],"details":"This update for opensc fixes the following issues:\n\n- CVE-2018-16391: Fixed a denial of service when handling responses from a Muscle Card (bsc#1106998)\n- CVE-2018-16392: Fixed a denial of service when handling responses from a TCOS Card (bsc#1106999)\n- CVE-2018-16393: Fixed buffer overflows when handling responses from Gemsafe V1 Smartcards (bsc#1108318)\n- CVE-2018-16418: Fixed buffer overflow when handling string concatenation in util_acl_to_str (bsc#1107039)\n- CVE-2018-16419: Fixed several buffer overflows when handling responses from a Cryptoflex card (bsc#1107107)\n- CVE-2018-16420: Fixed buffer overflows when handling responses from an ePass 2003 Card (bsc#1107097)\n- CVE-2018-16422: Fixed single byte buffer overflow when handling responses from an esteid Card (bsc#1107038)\n- CVE-2018-16423: Fixed double free when handling responses from a smartcard (bsc#1107037)\n- CVE-2018-16426: Fixed endless recursion when handling responses from an IAS-ECC card (bsc#1107034)\n- CVE-2018-16427: Fixed out of bounds reads when handling responses in OpenSC (bsc#1107033)\n\n","id":"SUSE-SU-2018:3622-2","modified":"2018-12-10T13:08:40Z","published":"2018-12-10T13:08:40Z","references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2018/suse-su-20183622-2/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1104812"},{"type":"REPORT","url":"https://bugzilla.suse.com/1106998"},{"type":"REPORT","url":"https://bugzilla.suse.com/1106999"},{"type":"REPORT","url":"https://bugzilla.suse.com/1107033"},{"type":"REPORT","url":"https://bugzilla.suse.com/1107034"},{"type":"REPORT","url":"https://bugzilla.suse.com/1107037"},{"type":"REPORT","url":"https://bugzilla.suse.com/1107038"},{"type":"REPORT","url":"https://bugzilla.suse.com/1107039"},{"type":"REPORT","url":"https://bugzilla.suse.com/1107097"},{"type":"REPORT","url":"https://bugzilla.suse.com/1107107"},{"type":"REPORT","url":"https://bugzilla.suse.com/1108318"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-16391"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-16392"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-16393"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-16418"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-16419"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-16420"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-16422"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-16423"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-16426"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-16427"}],"related":["CVE-2018-16391","CVE-2018-16392","CVE-2018-16393","CVE-2018-16418","CVE-2018-16419","CVE-2018-16420","CVE-2018-16422","CVE-2018-16423","CVE-2018-16426","CVE-2018-16427"],"summary":"Security update for opensc","upstream":["CVE-2018-16391","CVE-2018-16392","CVE-2018-16393","CVE-2018-16418","CVE-2018-16419","CVE-2018-16420","CVE-2018-16422","CVE-2018-16423","CVE-2018-16426","CVE-2018-16427"]}