CVE-2019-19480: Opensc Project Opensc

Medium severity, CVSS 4.6. EPSS: 0.6% chance of exploitation in the next 30 days.

An issue was discovered in OpenSC through 0.19.0 and 0.20.x through 0.20.0-rc3. libopensc/pkcs15-prkey.c has an incorrect free operation in sc_pkcs15_decode_prkdf_entry.

Affected products

  • Opensc Project Opensc: up to and including 0.19.0; version 0.20.0 only

Published 2019-12-01. Last modified 2026-06-17.