Multiple uses of uninitialized variables were found in libopensc that may lead to information disclosure or application crash. An attack requires a crafted USB device or smart card that would present the system with specially crafted responses to the APDUs
The code uses a variable that has not been initialized, leading to unpredictable or unintended results.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Opensc | Ubuntu | esm-apps/xenial | * |
| Opensc | Ubuntu | upstream | * |