CVE-2018-16422 describes a single-byte buffer overflow in OpenSC versions prior to 0.19.0-rc1, specifically within the sc_pkcs15emu_esteid_init function when processing responses from eID smartcards. This vulnerability affects the OpenSC project's OpenSC software. With a CVSS score of 6.6 (Medium), the attack requires physical access to the system and a crafted smartcard, potentially leading to a denial of service (application crash) or other unspecified impacts. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 0.18.0CPE matchmatch criteria | cpe:2.3:a:opensc_project:opensc:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.