Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cf2w-h975-2fpg

Опубликовано: 04 сент. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 3.9

Описание

A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. When buffers are partially filled with data, initialized parts of the buffer can be incorrectly accessed.

A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. When buffers are partially filled with data, initialized parts of the buffer can be incorrectly accessed.

EPSS

Процентиль: 22%
0.00302
Низкий

3.9 Low

CVSS3

Дефекты

CWE-457
CWE-908

Связанные уязвимости

CVSS3: 3.9
ubuntu
почти 2 года назад

A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. Insufficient or missing checking of return values of functions leads to unexpected work with variables that have not been initialized.

CVSS3: 3.9
redhat
почти 2 года назад

A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. Insufficient or missing checking of return values of functions leads to unexpected work with variables that have not been initialized.

CVSS3: 3.9
nvd
почти 2 года назад

A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. Insufficient or missing checking of return values of functions leads to unexpected work with variables that have not been initialized.

CVSS3: 3.9
msrc
11 месяцев назад

Libopensc: uninitialized values after incorrect or missing checking return values of functions in libopensc

CVSS3: 3.9
debian
почти 2 года назад

A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, min ...

EPSS

Процентиль: 22%
0.00302
Низкий

3.9 Low

CVSS3

Дефекты

CWE-457
CWE-908