PT-2023-8907 · Opensc+4 · Opensc+4

Tej Rathi

·

Published

2023-11-06

·

Updated

2025-01-27

·

CVE-2023-4535

CVSS v3.1

4.5

Medium

VectorAV:P/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions OpenSC (affected versions not specified)
Description An out-of-bounds read vulnerability was found in OpenSC packages within the MyEID driver when handling symmetric key encryption. Exploiting this flaw requires an attacker to have physical access to the computer and a specially crafted USB device or smart card. This flaw allows the attacker to manipulate APDU responses and potentially gain unauthorized access to sensitive data, compromising the system's security.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Out of bounds Read

Weakness Enumeration

Related Identifiers

ALSA-2023:7879
ALT-PU-2023-8056
ALT-PU-2023-8077
ALT-PU-2023-8185
ALT-PU-2024-7018
AZL-31945
AZL-35076
BDU:2024-02587
CVE-2023-4535
OPENSUSE-SU-2024:13314-1
RHSA-2023:7879
RHSA-2023_7879
ROSA-SA-2025-2580

Affected Products

Alt Linux
Almalinux
Opensc
Red Hat
Red Os