Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9c2g-6v5v-57qg

Опубликовано: 04 сент. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 3.9

Описание

A vulnerability was found in the pkcs15-init tool in OpenSC. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. When buffers are partially filled with data, initialized parts of the buffer can be incorrectly accessed.

A vulnerability was found in the pkcs15-init tool in OpenSC. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. When buffers are partially filled with data, initialized parts of the buffer can be incorrectly accessed.

EPSS

Процентиль: 24%
0.00318
Низкий

3.9 Low

CVSS3

Дефекты

CWE-120

Связанные уязвимости

CVSS3: 3.9
ubuntu
около 2 лет назад

A vulnerability was found in the pkcs15-init tool in OpenSC. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. When buffers are partially filled with data, initialized parts of the buffer can be incorrectly accessed.

CVSS3: 3.9
redhat
около 2 лет назад

A vulnerability was found in the pkcs15-init tool in OpenSC. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. When buffers are partially filled with data, initialized parts of the buffer can be incorrectly accessed.

CVSS3: 3.9
nvd
около 2 лет назад

A vulnerability was found in the pkcs15-init tool in OpenSC. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. When buffers are partially filled with data, initialized parts of the buffer can be incorrectly accessed.

CVSS3: 3.9
msrc
около 1 года назад

Libopensc: incorrect handling of the length of buffers or files in pkcs15init

CVSS3: 3.9
debian
около 2 лет назад

A vulnerability was found in the pkcs15-init tool in OpenSC. An attack ...

EPSS

Процентиль: 24%
0.00318
Низкий

3.9 Low

CVSS3

Дефекты

CWE-120