PT-2026-29080 · Opensc · Opensc
Published
2025-01-01
·
Updated
2026-06-15
·
CVE-2025-49010
CVSS v3.1
6.8
Medium
| Vector | AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
OpenSC versions prior to 0.27.0
Description
OpenSC is a set of open source smart card tools and middleware. A stack-based buffer overflow can occur in the
GET RESPONSE function when a user or administrator utilizes a token, allowing an attacker with physical access to the computer to potentially cause a write to the stack. The attack requires a crafted USB device or smart card presenting specially crafted responses to the APDUs.Recommendations
Update to version 0.27.0 or later.
Exploit
Fix
Stack Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Opensc