PT-2024-9396 · Opensc+6 · Opensc+6

Matteo Marini

·

Published

2024-09-03

·

Updated

2025-10-14

·

CVE-2024-45619

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: OpenSC (affected versions not specified)
Description: A buffer overflow issue in OpenSC tools and modules allows an attacker to potentially gain unauthorized access to protected information. The vulnerability can be exploited by using a crafted USB device or smart card that presents the system with a specially crafted response to APDUs, leading to incorrect access of initialized parts of partially filled buffers.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2025-12697
ALT-PU-2025-12701
AZL-48757
AZL-48804
BDU:2024-11088
CVE-2024-45619
DLA-4004-1
MGASA-2025-0096
OESA-2024-2245
OPENSUSE-SU-2024:14382-1
OPENSUSE-SU-2024_3444-1
OPENSUSE-SU-2024_3445-1
SUSE-SU-2024:3443-1
SUSE-SU-2024:3444-1
SUSE-SU-2024:3445-1
SUSE-SU-2024:3517-1
SUSE-SU-2025:20072-1
SUSE-SU-2025:20671-1
USN-7346-1
USN-7346-2

Affected Products

Alt Linux
Astra Linux
Linuxmint
Opensc
Red Os
Suse
Ubuntu