Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f2v6-mw6x-qmwc

Опубликовано: 04 сент. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 3.9

Описание

A vulnerability was found in pkcs15-init in OpenSC. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. When buffers are partially filled with data, initialized parts of the buffer can be incorrectly accessed.

A vulnerability was found in pkcs15-init in OpenSC. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. When buffers are partially filled with data, initialized parts of the buffer can be incorrectly accessed.

EPSS

Процентиль: 24%
0.00311
Низкий

3.9 Low

CVSS3

Дефекты

CWE-457
CWE-908

Связанные уязвимости

CVSS3: 3.9
ubuntu
около 2 лет назад

A vulnerability was found in pkcs15-init in OpenSC. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. Insufficient or missing checking of return values of functions leads to unexpected work with variables that have not been initialized.

CVSS3: 3.9
redhat
около 2 лет назад

A vulnerability was found in pkcs15-init in OpenSC. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. Insufficient or missing checking of return values of functions leads to unexpected work with variables that have not been initialized.

CVSS3: 3.9
nvd
около 2 лет назад

A vulnerability was found in pkcs15-init in OpenSC. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. Insufficient or missing checking of return values of functions leads to unexpected work with variables that have not been initialized.

CVSS3: 3.9
msrc
около 1 года назад

Libopensc: uninitialized values after incorrect or missing checking return values of functions in pkcs15init

CVSS3: 3.9
debian
около 2 лет назад

A vulnerability was found in pkcs15-init in OpenSC. An attacker could ...

EPSS

Процентиль: 24%
0.00311
Низкий

3.9 Low

CVSS3

Дефекты

CWE-457
CWE-908