PT-2024-9395 · Opensc+6 · Opensc+6
CVSS v2.0
4.6
Medium
| Vector | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
OpenSC (affected versions not specified)
Description
A memory out-of-bounds read issue exists in the
pkcs15-init tool. An attacker can exploit this by using a specially crafted USB device or smart card that provides a manipulated response to APDUs (Application Protocol Data Units), which are communication units used between a smart card and a reader. This allows incorrect access to initialized parts of the buffer when it is only partially filled with data, potentially leading to unauthorized access to protected information.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
DoS
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Astra Linux
Linuxmint
Opensc
Red Os
Suse
Ubuntu