Alpine: multiple opensc packages: security update to 0.19.0-r0

medium Tenable Cloud Security Plugin ID 406028

Description

There are packages installed that are affected by multiple vulnerabilities referenced in the following CVEs:

- A double free when handling responses from an HSM Card in sc_pkcs15emu_sc_hsm_init in libopensc/pkcs15-sc-
hsm.c in OpenSC before 0.19.0-rc1 could be used by attackers able to supply crafted smartcards to cause a
denial of service (application crash) or possibly have unspecified other impact. (CVE-2018-16425)

- Several buffer overflows when handling responses from a Muscle Card in muscle_list_files in
libopensc/card-muscle.c in OpenSC before 0.19.0-rc1 could be used by attackers able to supply crafted
smartcards to cause a denial of service (application crash) or possibly have unspecified other impact.
(CVE-2018-16391)

- Several buffer overflows when handling responses from a TCOS Card in tcos_select_file in libopensc/card-
tcos.c in OpenSC before 0.19.0-rc1 could be used by attackers able to supply crafted smartcards to cause a
denial of service (application crash) or possibly have unspecified other impact. (CVE-2018-16392)

- Several buffer overflows when handling responses from a Gemsafe V1 Smartcard in gemsafe_get_cert_len in
libopensc/pkcs15-gemsafeV1.c in OpenSC before 0.19.0-rc1 could be used by attackers able to supply crafted
smartcards to cause a denial of service (application crash) or possibly have unspecified other impact.
(CVE-2018-16393)

- A buffer overflow when handling string concatenation in util_acl_to_str in tools/util.c in OpenSC before
0.19.0-rc1 could be used by attackers able to supply crafted smartcards to cause a denial of service
(application crash) or possibly have unspecified other impact. (CVE-2018-16418)

See Also

https://security.alpinelinux.org/vuln/CVE-2018-16391

https://security.alpinelinux.org/vuln/CVE-2018-16392

https://security.alpinelinux.org/vuln/CVE-2018-16393

https://security.alpinelinux.org/vuln/CVE-2018-16418

https://security.alpinelinux.org/vuln/CVE-2018-16419

https://security.alpinelinux.org/vuln/CVE-2018-16420

https://security.alpinelinux.org/vuln/CVE-2018-16421

https://security.alpinelinux.org/vuln/CVE-2018-16422

https://security.alpinelinux.org/vuln/CVE-2018-16423

https://security.alpinelinux.org/vuln/CVE-2018-16424

https://security.alpinelinux.org/vuln/CVE-2018-16425

https://security.alpinelinux.org/vuln/CVE-2018-16426

https://security.alpinelinux.org/vuln/CVE-2018-16427

Plugin Details

Severity: Medium

ID: 406028

Version: Revision 1.26

Type: Local

Published: 10/31/2023

Updated: 12/4/2025

Supported Sensors: Agentless Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 6.7

CVSS v2

Risk Factor: Medium

Base Score: 4.6

Temporal Score: 3.6

Vector: CVSS2#AV:L/AC:L/Au:N/C:P/I:P/A:P

CVSS Score Source: CVE-2018-16425

CVSS v3

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 6.1

Vector: CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

CVSS Score Source: CVE-2018-16393

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Vulnerability Publication Date: 2/3/2018

Reference Information

CVE: CVE-2018-16391, CVE-2018-16392, CVE-2018-16393, CVE-2018-16418, CVE-2018-16419, CVE-2018-16420, CVE-2018-16421, CVE-2018-16422, CVE-2018-16423, CVE-2018-16424, CVE-2018-16425, CVE-2018-16426, CVE-2018-16427

BID: 107519, 107573, 107575, 107576, 107661, 108109, 108112