Описание
A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. The following problems were caused by insufficient control of the response APDU buffer and its length when communicating with the card.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | not-affected | |
| esm-apps-legacy/xenial | not-affected | code not present |
| esm-apps/bionic | not-affected | code not present |
| esm-apps/focal | released | 0.20.0-3ubuntu0.1~esm4 |
| esm-apps/jammy | released | 0.22.0-1ubuntu2+esm1 |
| esm-apps/noble | released | 0.25.0~rc1-1ubuntu0.1~esm1 |
| esm-apps/resolute | not-affected | |
| esm-apps/xenial | not-affected | code not present |
| focal | ignored | end of standard support, was needed |
| jammy | needed |
Показывать по
Ссылки на источники
EPSS
3.9 Low
CVSS3
Связанные уязвимости
A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. The following problems were caused by insufficient control of the response APDU buffer and its length when communicating with the card.
A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. The following problems were caused by insufficient control of the response APDU buffer and its length when communicating with the card.
Libopensc: uninitialized values after incorrect check or usage of apdu response values in libopensc
A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, min ...
A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. When buffers are partially filled with data, initialized parts of the buffer can be incorrectly accessed.
EPSS
3.9 Low
CVSS3