PT-2024-9395 · Opensc+6 · Opensc+6

·

CVE-2024-45620

·

Published

2024-09-02

·

Updated

2026-06-30

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions OpenSC (affected versions not specified)
Description A memory out-of-bounds read issue exists in the pkcs15-init tool. An attacker can exploit this by using a specially crafted USB device or smart card that provides a manipulated response to APDUs (Application Protocol Data Units), which are communication units used between a smart card and a reader. This allows incorrect access to initialized parts of the buffer when it is only partially filled with data, potentially leading to unauthorized access to protected information.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2025-12697
ALT-PU-2025-12701
AZL-48711
AZL-48817
BDU:2024-11087
CVE-2024-45620
DLA-4004-1
MGASA-2025-0096
OESA-2024-2245
OPENSUSE-SU-2024:14382-1
OPENSUSE-SU-2024_3444-1
OPENSUSE-SU-2024_3445-1
SUSE-SU-2024:3443-1
SUSE-SU-2024:3444-1
SUSE-SU-2024:3445-1
SUSE-SU-2024:3517-1
SUSE-SU-2025:20072-1
SUSE-SU-2025:20671-1
USN-7346-1
USN-7346-2
USN-7346-3

Affected Products

Alt Linux
Astra Linux
Linuxmint
Opensc
Red Os
Suse
Ubuntu