OpenSC before 0.20.0-rc1 has an out-of-bounds access of an ASN.1 Bitstring in decodebitstring in libopensc/asn1.c.
{ "vanir_signatures": [ { "id": "CVE-2019-15945-5ff9212e", "signature_type": "Line", "target": { "file": "src/libopensc/asn1.c" }, "deprecated": false, "digest": { "line_hashes": [ "297175338200415450495469453137505148979", "324464793528311656715900885897677107677", "235162866907379193967776824386251535809", "148892391738533823772808675824081347164", "271007510155698596031020343162910857595", "17928902979717757606177869801051367107", "6680214412565745825158616163531721129", "308450731521761626803739219073195203892", "235313599250259173294102152659145129581", "184459165867828565842888035184684183514", "66599990226266053176047532713479330761", "234365475496651906006414592092147041548" ], "threshold": 0.9 }, "signature_version": "v1", "source": "https://github.com/opensc/opensc/commit/412a6142c27a5973c61ba540e33cdc22d5608e68" }, { "id": "CVE-2019-15945-b438983c", "signature_type": "Function", "target": { "file": "src/libopensc/asn1.c", "function": "decode_bit_string" }, "deprecated": false, "digest": { "length": 675.0, "function_hash": "73470549151581179276510363648036828424" }, "signature_version": "v1", "source": "https://github.com/opensc/opensc/commit/412a6142c27a5973c61ba540e33cdc22d5608e68" } ] }