PT-2024-9395 · Opensc+6 · Opensc+6

Matteo Marini

·

Published

2024-09-02

·

Updated

2025-10-14

·

CVE-2024-45620

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: OpenSC pkcs15-init tool (affected versions not specified)
Description: The issue is related to a buffer overflow in the pkcs15-init tool of the OpenSC software suite. An attacker could exploit this by using a specially crafted USB device or smart card, presenting the system with a tailored response to APDUs. This could lead to unauthorized access to protected information when buffers are partially filled with data and initialized parts of the buffer are accessed incorrectly.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Buffer Overflow

Weakness Enumeration

Related Identifiers

ALT-PU-2025-12697
ALT-PU-2025-12701
AZL-48711
AZL-48817
BDU:2024-11087
CVE-2024-45620
DLA-4004-1
MGASA-2025-0096
OESA-2024-2245
OPENSUSE-SU-2024:14382-1
OPENSUSE-SU-2024_3444-1
OPENSUSE-SU-2024_3445-1
SUSE-SU-2024:3443-1
SUSE-SU-2024:3444-1
SUSE-SU-2024:3445-1
SUSE-SU-2024:3517-1
SUSE-SU-2025:20072-1
SUSE-SU-2025:20671-1
USN-7346-1
USN-7346-2
USN-7346-3

Affected Products

Alt Linux
Astra Linux
Linuxmint
Opensc
Red Os
Suse
Ubuntu