Use-after-free vulnerability in pcsc-lite before 1.8.20 allows a remote attackers to cause denial of service (crash) via a command that uses "cardsList" after the handle has been released through the SCardReleaseContext function.
{
"binaries": [
{
"binary_version": "1.8.14-1ubuntu1.16.04.1",
"binary_name": "libpcsclite-dev"
},
{
"binary_version": "1.8.14-1ubuntu1.16.04.1",
"binary_name": "libpcsclite1"
},
{
"binary_version": "1.8.14-1ubuntu1.16.04.1",
"binary_name": "pcscd"
}
],
"availability": "No subscription required"
}