PT-2023-22410 · Opensc+8 · Opensc+8

Sandipan Roy

·

Published

2023-05-30

·

Updated

2025-04-09

·

CVE-2023-2977

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions OpenSC (affected versions not specified)
Description A security flaw in OpenSC causes a buffer overrun vulnerability in pkcs15 cardos have verifyrc package. An attacker can supply a smart card package with malformed ASN1 context. The cardos have verifyrc package function scans the ASN1 buffer for 2 tags, where the remaining length is wrongly calculated due to a moved starting pointer. This leads to a possible heap-based buffer out of bounds read. In cases where ASAN is enabled while compiling, this causes a crash. Further information leak or more damage is possible.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Buffer Overflow

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2023:6587
ALSA-2023:7160
ALT-PU-2023-8056
ALT-PU-2023-8077
ALT-PU-2023-8185
ALT-PU-2024-7018
AZL-27012
AZL-35073
BDU:2025-04907
CESA-2023_7160
CVE-2023-2977
DLA-3463-1
DLA-4004-1
MGASA-2023-0222
OESA-2023-1678
OESA-2023-1679
OPENSUSE-SU-2024:12968-1
RHSA-2023:6587
RHSA-2023:7160
RHSA-2023_6587
RHSA-2023_7160
SUSE-SU-2023:2466-1
SUSE-SU-2023:2508-1
SUSE-SU-2023:2516-1
SUSE-SU-2023_2466-1
SUSE-SU-2023_2508-1
SUSE-SU-2023_2516-1
USN-7346-1
USN-7346-2
USN-7346-3

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Linuxmint
Opensc
Red Hat
Suse
Ubuntu