Vulnerability Description
Stack buffer overflow issues were found in Opensc before version 0.22.0 in various places that could potentially crash programs using the library.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Opensc Project | Opensc | < 0.22.0 |
| Fedoraproject | Fedora | 33 |
Related Weaknesses (CWE)
References
- https://bugzilla.redhat.com/show_bug.cgi?id=2016448Issue TrackingMailing ListPatch
- https://github.com/OpenSC/OpenSC/commit/1252aca9PatchThird Party Advisory
- https://github.com/OpenSC/OpenSC/commit/456ac566PatchThird Party Advisory
- https://github.com/OpenSC/OpenSC/commit/7114fb71PatchThird Party Advisory
- https://github.com/OpenSC/OpenSC/commit/78cdab94PatchThird Party Advisory
- https://github.com/OpenSC/OpenSC/commit/ae1cf0bePatchThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2023/06/msg00025.html
- https://security.gentoo.org/glsa/202209-03Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2016448Issue TrackingMailing ListPatch
- https://github.com/OpenSC/OpenSC/commit/1252aca9PatchThird Party Advisory
- https://github.com/OpenSC/OpenSC/commit/456ac566PatchThird Party Advisory
- https://github.com/OpenSC/OpenSC/commit/7114fb71PatchThird Party Advisory
- https://github.com/OpenSC/OpenSC/commit/78cdab94PatchThird Party Advisory
- https://github.com/OpenSC/OpenSC/commit/ae1cf0bePatchThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2023/06/msg00025.html
FAQ
What is CVE-2021-42782?
CVE-2021-42782 is a vulnerability with a CVSS score of 5.3 (MEDIUM). Stack buffer overflow issues were found in Opensc before version 0.22.0 in various places that could potentially crash programs using the library.
How severe is CVE-2021-42782?
CVE-2021-42782 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-42782?
Check the references section above for vendor advisories and patch information. Affected products include: Opensc Project Opensc, Fedoraproject Fedora.