CVE-2019-20792

Source
https://cve.org/CVERecord?id=CVE-2019-20792
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-20792.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2019-20792
Downstream
DEBIAN (1)
openSUSE (2)
RHSA (1)
SUSE (2)
UBUNTU (1)
Related
Published
2020-04-29T04:15:17Z
Modified
2026-08-07T14:53:02Z
Severity
  • 6.8 (Medium) CVSS_V3 - CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

OpenSC before 0.20.0 has a double free in coolkey_free_private_data because coolkey_add_object in libopensc/card-coolkey.c lacks a uniqueness check.

References

Affected packages

Git / github.com/opensc/opensc

Affected ranges

Type
GIT
Repo
https://github.com/opensc/opensc
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Database specific
Show details
{
    "cpe":  "cpe:2.3:a:opensc_project:opensc:*:*:*:*:*:*:*:*",
    "extracted_events":  [
        {
            "introduced":  "0"
        },
        {
            "fixed":  "0.20.0"
        }
    ],
    "source":  [
        "CPE_RANGE",
        "REFERENCES"
    ]
}

Affected versions

0.*
0.12.2
0.12.2-rc1
0.13.0
0.13.0pre1
0.13.0rc1
0.14.0
0.14.0rc2
0.14.0rtm
0.15.0
0.16.0
0.17.0
0.17.0-rc1
0.17.0-rc2
0.18.0
0.18.0-rc1
0.18.0-rc2
0.19.0
0.19.0-rc1
0.20.0-rc1
0.20.0-rc2
0.20.0-rc3
0.20.0-rc4
v0.*
v0.12.2
v0.16.0-pre1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-20792.json"
vanir_signatures
[
    {
        "deprecated":  false,
        "digest":  {
            "function_hash":  "293648382138511495160968861622353662031",
            "length":  2619
        },
        "id":  "CVE-2019-20792-0e4109b3",
        "signature_type":  "Function",
        "signature_version":  "v1",
        "source":  "https://github.com/opensc/opensc/commit/45e29056ccde422e70ed3585084a7f150c632515",
        "target":  {
            "file":  "src/tests/fuzzing/fuzz_pkcs15_reader.c",
            "function":  "LLVMFuzzerTestOneInput"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "230985030794508757992760968719559967350",
                "310435344726459438381937301013045244530",
                "288673917574911987998876666203952460375"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2019-20792-3c6d3c4a",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://github.com/opensc/opensc/commit/c246f6f69a749d4f68626b40795a4f69168008f4",
        "target":  {
            "file":  "src/libopensc/card-coolkey.c"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "194062470009936436447945246988331101219",
                "251408580405775135383116960595976968951",
                "284045830406911495116073497720354821007",
                "270953615497185537070235313685442968422",
                "20393014985081258602878277868967455511",
                "91070933187673124866303201171236791528",
                "240044258610078274294209636274322753269",
                "302641261595298239604372272751171178922"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2019-20792-775a11f1",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://github.com/opensc/opensc/commit/45e29056ccde422e70ed3585084a7f150c632515",
        "target":  {
            "file":  "src/tests/fuzzing/fuzz_pkcs15_reader.c"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "function_hash":  "81983556100758335818887154183925867305",
            "length":  716
        },
        "id":  "CVE-2019-20792-f5fba478",
        "signature_type":  "Function",
        "signature_version":  "v1",
        "source":  "https://github.com/opensc/opensc/commit/c246f6f69a749d4f68626b40795a4f69168008f4",
        "target":  {
            "file":  "src/libopensc/card-coolkey.c",
            "function":  "coolkey_add_object"
        }
    }
]
vanir_signatures_modified
"2026-08-07T14:53:02Z"