{"id":"SUSE-SU-2018:3621-1","summary":"Security update for opensc","details":"This update for opensc fixes the following issues:\n\n- CVE-2018-16391: Fixed a denial of service when handling responses from a Muscle Card (bsc#1106998)\n- CVE-2018-16392: Fixed a denial of service when handling responses from a TCOS Card (bsc#1106999)\n- CVE-2018-16393: Fixed buffer overflows when handling responses from Gemsafe V1 Smartcards (bsc#1108318)\n- CVE-2018-16418: Fixed buffer overflow when handling string concatenation in util_acl_to_str (bsc#1107039)\n- CVE-2018-16419: Fixed several buffer overflows when handling responses from a Cryptoflex card (bsc#1107107)\n- CVE-2018-16422: Fixed single byte buffer overflow when handling responses from an esteid Card (bsc#1107038)\n- CVE-2018-16423: Fixed double free when handling responses from a smartcard (bsc#1107037)\n- CVE-2018-16427: Fixed out of bounds reads when handling responses in OpenSC (bsc#1107033)\n\n","modified":"2026-03-11T07:00:03.199512Z","published":"2018-11-05T16:59:27Z","related":["CVE-2018-16391","CVE-2018-16392","CVE-2018-16393","CVE-2018-16418","CVE-2018-16419","CVE-2018-16422","CVE-2018-16423","CVE-2018-16427"],"upstream":["CVE-2018-16391","CVE-2018-16392","CVE-2018-16393","CVE-2018-16418","CVE-2018-16419","CVE-2018-16422","CVE-2018-16423","CVE-2018-16427"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2018/suse-su-20183621-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1104812"},{"type":"REPORT","url":"https://bugzilla.suse.com/1106998"},{"type":"REPORT","url":"https://bugzilla.suse.com/1106999"},{"type":"REPORT","url":"https://bugzilla.suse.com/1107033"},{"type":"REPORT","url":"https://bugzilla.suse.com/1107037"},{"type":"REPORT","url":"https://bugzilla.suse.com/1107038"},{"type":"REPORT","url":"https://bugzilla.suse.com/1107039"},{"type":"REPORT","url":"https://bugzilla.suse.com/1107107"},{"type":"REPORT","url":"https://bugzilla.suse.com/1108318"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-16391"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-16392"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-16393"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-16418"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-16419"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-16422"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-16423"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-16427"}],"affected":[{"package":{"name":"opensc","ecosystem":"SUSE:Linux Enterprise Software Development Kit 11 SP4","purl":"pkg:rpm/suse/opensc&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2011%20SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.11.6-5.27.3.1"}]}],"ecosystem_specific":{"binaries":[{"opensc-devel":"0.11.6-5.27.3.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2018:3621-1.json"}},{"package":{"name":"opensc","ecosystem":"SUSE:Linux Enterprise Server 11 SP4","purl":"pkg:rpm/suse/opensc&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.11.6-5.27.3.1"}]}],"ecosystem_specific":{"binaries":[{"opensc":"0.11.6-5.27.3.1","libopensc2-32bit":"0.11.6-5.27.3.1","libopensc2-x86":"0.11.6-5.27.3.1","libopensc2":"0.11.6-5.27.3.1","opensc-32bit":"0.11.6-5.27.3.1","opensc-x86":"0.11.6-5.27.3.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2018:3621-1.json"}},{"package":{"name":"opensc","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 11 SP4","purl":"pkg:rpm/suse/opensc&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2011%20SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.11.6-5.27.3.1"}]}],"ecosystem_specific":{"binaries":[{"libopensc2-32bit":"0.11.6-5.27.3.1","libopensc2-x86":"0.11.6-5.27.3.1","libopensc2":"0.11.6-5.27.3.1","opensc-32bit":"0.11.6-5.27.3.1","opensc-x86":"0.11.6-5.27.3.1","opensc":"0.11.6-5.27.3.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2018:3621-1.json"}}],"schema_version":"1.7.5"}