PT-2023-22410 · Opensc+8 · Opensc+8
Sandipan Roy
·
Publicado
2023-05-30
·
Atualizado
2025-04-09
·
CVE-2023-2977
CVSS v3.1
7.1
Alta
| Vetor | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
OpenSC (affected versions not specified)
Description
A security flaw in OpenSC causes a buffer overrun vulnerability in
pkcs15 cardos have verifyrc package. An attacker can supply a smart card package with malformed ASN1 context. The cardos have verifyrc package function scans the ASN1 buffer for 2 tags, where the remaining length is wrongly calculated due to a moved starting pointer. This leads to a possible heap-based buffer out of bounds read. In cases where ASAN is enabled while compiling, this causes a crash. Further information leak or more damage is possible.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Buffer Overflow
Out of bounds Read
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Alt Linux
Almalinux
Astra Linux
Centos
Linuxmint
Opensc
Red Hat
Suse
Ubuntu