VDB
GCVE-VVD-MAGEIA-2020-26
GCVE-VVD-MAGEIA-2020-26
Advisory Published
Updated opensc packages fix security vulnerabilities:
sc_context_create in ctx.c in libopensc in OpenSC 0.19.0 has a memory
leak, as demonstrated by a call from eidenv (CVE-2019-6502).
OpenSC before 0.20.0-rc1 has an out-of-bounds access of an ASN.1 Bitstring
in decode_bit_string in libopensc/asn1.c (CVE-2019-15945).
OpenSC before 0.20.0-rc1 has an out-of-bounds access of an ASN.1 Octet
string in asn1_decode_entry in libopensc/asn1.c (CVE-2019-15946).
An issue was discovered in OpenSC through 0.19.0 and 0.20.x through
0.20.0-rc3. libopensc/card-setcos.c has an incorrect read operation during
parsing of a SETCOS file attribute (CVE-2019-19479).
An issue was discovered in OpenSC through 0.19.0 and 0.20.x through
0.20.0-rc3. libopensc/pkcs15-prkey.c has an incorrect free operation in
sc_pkcs15_decode_prkdf_entry (CVE-2019-19480).
An issue was discovered in OpenSC through 0.19.0 and 0.20.x through
0.20.0-rc3. libopensc/card-cac1.c mishandles buffer limits for CAC
certificates (CVE-2019-19481).
The opensc package has been updated to version 0.20.0, which has fixes for
these issues and other improvements.
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Mageia | opensc | 0 (affected), 0.20.0-1.mga7 (unaffected) | — |
| Mageia | flash-player-plugin | 0 (affected), 32.0.0.314-1.mga7.nonfree (unaffected) | — |
Aliases
Transitive aliases
RHSA-2023:7879BDU:2024-02587GHSA-q94h-rrgw-hvcqCVE-2021-42780CVE-2018-16420GHSA-634q-77fv-9cq7GHSA-x65v-c8ff-h2m3GHSA-99x7-636q-6hvjGSD-2021-42779GHSA-4qgx-xw7p-6ggpGHSA-h7qm-v38r-6f4cBDU:2024-02588BDU:2022-00268WID-SEC-W-2023-2407CVE-2021-42781CVE-2021-42782GHSA-m2w8-wqfw-qchxGHSA-7wjg-mhwg-m2rcOPENSUSE-SU-2024:13314-1SUSE-SU-2021:1168-1CVE-2021-42779SUSE-SU-2023:4089-1CVE-2023-40660CNVD-2019-45406CVE-2008-2235CVE-2018-16426CVE-2018-16427GHSA-547v-83cc-5hqgALSA-2021:1600GHSA-rcjw-9639-853hBDU:2025-12490BDU:2022-00273CVE-2019-20792GHSA-h2m7-5hj2-cj6cBDU:2025-12491GHSA-955c-643p-2354GHSA-x56f-5g95-vmfxCVE-2023-40661ALSA-2023:7876CVE-2018-16422GHSA-7c8p-jqm5-mj3qOPENSUSE-SU-2024:11613-1SUSE-SU-2021:3582-1GHSA-j7gx-7q9r-7wp6WID-SEC-W-2023-2500MSRC_CVE-2023-40660OPENSUSE-SU-2024:11123-1CVE-2018-16393GHSA-8cph-r8x9-fxx9BDU:2024-02589GSD-2023-40660MSRC_CVE-2023-4535GHSA-phh2-j3h6-vqr9SUSE-SU-2022:1156-1BDU:2015-09340GHSA-29r7-6cj9-gh39GSD-2023-40661GSD-2023-4535CVE-2018-16424GHSA-37c8-gm6x-ffchGHSA-w4mm-38jx-q774RHSA-2023:7876CVE-2023-4535SUSE-SU-2022:1041-1BDU:2022-00332GHSA-rmfw-qmvr-x823CVE-2020-26571CVE-2020-26572CVE-2020-26570CVE-2018-16419MSRC_CVE-2021-42779VVD-MAGEIA-2021-37VVD-MAGEIA-2021-512GHSA-93j9-4rqq-x6grSUSE-SU-2023:4065-1GHSA-5v2c-mrj8-6f2mSUSE-SU-2023:4104-1BDU:2025-12492GHSA-xq25-8g7f-6hc5VVD-MAGEIA-2019-19GHSA-35jr-36cj-2w6gALSA-2023:7879GHSA-7635-x5f9-5458GHSA-wfg8-cwx5-w8xcBDU:2022-00271CVE-2018-16391CVE-2018-16423BDU:2025-12489GHSA-f432-537h-hwj6GHSA-38x5-6rjp-vc28MSRC_CVE-2023-40661CVE-2018-16421GHSA-2c2j-2pgv-gfgcOPENSUSE-SU-2021:0565-1GHSA-mqh2-9c27-h9wqGSD-2019-19480CVE-2018-16392CVE-2018-16418CVE-2018-16425
References
Browse GCVE Records
100 records in the GCVE database · Updated April 16, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.