CVE-2019-19481 log

Severity Medium
Remote No
Type Denial of service
An issue was discovered in OpenSC before 0.20.0. libopensc/card-cac1.c mishandles buffer limits for CAC certificates, leading to an out-of-bounds read.
Group Package Affected Fixed Severity Status Ticket
AVG-1106 opensc 0.19.0-2 0.20.0-1 Medium Fixed FS#65082
Date Advisory Group Package Severity Type
04 Mar 2020 ASA-202003-2 AVG-1106 opensc Medium denial of service
The existing next_len = MIN(left, apdu.sw2); was calculated without taking into account the already read bytes (len should have been decremented before the call to MIN()).