Логотип exploitDog
bind:"BDU:2025-04907" OR bind:"CVE-2023-2977"
Консоль
Логотип exploitDog

exploitDog

bind:"BDU:2025-04907" OR bind:"CVE-2023-2977"

Количество 12

Количество 12

fstec логотип

BDU:2025-04907

больше 2 лет назад

Уязвимость функции cardos_have_verifyrc_package набора программных инструментов и библиотек для работы со смарт-картами OpenSC, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.1
EPSS: Низкий
ubuntu логотип

CVE-2023-2977

больше 2 лет назад

A vulnerbility was found in OpenSC. This security flaw cause a buffer overrun vulnerability in pkcs15 cardos_have_verifyrc_package. The attacker can supply a smart card package with malformed ASN1 context. The cardos_have_verifyrc_package function scans the ASN1 buffer for 2 tags, where remaining length is wrongly caculated due to moved starting pointer. This leads to possible heap-based buffer oob read. In cases where ASAN is enabled while compiling this causes a crash. Further info leak or more damage is possible.

CVSS3: 7.1
EPSS: Низкий
redhat логотип

CVE-2023-2977

больше 2 лет назад

A vulnerbility was found in OpenSC. This security flaw cause a buffer overrun vulnerability in pkcs15 cardos_have_verifyrc_package. The attacker can supply a smart card package with malformed ASN1 context. The cardos_have_verifyrc_package function scans the ASN1 buffer for 2 tags, where remaining length is wrongly caculated due to moved starting pointer. This leads to possible heap-based buffer oob read. In cases where ASAN is enabled while compiling this causes a crash. Further info leak or more damage is possible.

CVSS3: 6.3
EPSS: Низкий
nvd логотип

CVE-2023-2977

больше 2 лет назад

A vulnerbility was found in OpenSC. This security flaw cause a buffer overrun vulnerability in pkcs15 cardos_have_verifyrc_package. The attacker can supply a smart card package with malformed ASN1 context. The cardos_have_verifyrc_package function scans the ASN1 buffer for 2 tags, where remaining length is wrongly caculated due to moved starting pointer. This leads to possible heap-based buffer oob read. In cases where ASAN is enabled while compiling this causes a crash. Further info leak or more damage is possible.

CVSS3: 7.1
EPSS: Низкий
msrc логотип

CVE-2023-2977

около 2 лет назад

CVSS3: 7.1
EPSS: Низкий
debian логотип

CVE-2023-2977

больше 2 лет назад

A vulnerbility was found in OpenSC. This security flaw cause a buffer ...

CVSS3: 7.1
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:2516-1

около 2 лет назад

Security update for opensc

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:2508-1

около 2 лет назад

Security update for opensc

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:2466-1

около 2 лет назад

Security update for opensc

EPSS: Низкий
github логотип

GHSA-p22r-5f28-437x

больше 2 лет назад

A vulnerbility was found in OpenSC. This security flaw cause a buffer overrun vulnerability in pkcs15 cardos_have_verifyrc_package. The attacker can supply a smart card package with malformed ASN1 context. The cardos_have_verifyrc_package function scans the ASN1 buffer for 2 tags, where remaining length is wrongly caculated due to moved starting pointer. This leads to possible heap-based buffer oob read. In cases where ASAN is enabled while compiling this causes a crash. Further info leak or more damage is possible.

CVSS3: 7.1
EPSS: Низкий
oracle-oval логотип

ELSA-2023-7160

почти 2 года назад

ELSA-2023-7160: opensc security and bug fix update (LOW)

EPSS: Низкий
oracle-oval логотип

ELSA-2023-6587

почти 2 года назад

ELSA-2023-6587: opensc security update (LOW)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2025-04907

Уязвимость функции cardos_have_verifyrc_package набора программных инструментов и библиотек для работы со смарт-картами OpenSC, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.1
0%
Низкий
больше 2 лет назад
ubuntu логотип
CVE-2023-2977

A vulnerbility was found in OpenSC. This security flaw cause a buffer overrun vulnerability in pkcs15 cardos_have_verifyrc_package. The attacker can supply a smart card package with malformed ASN1 context. The cardos_have_verifyrc_package function scans the ASN1 buffer for 2 tags, where remaining length is wrongly caculated due to moved starting pointer. This leads to possible heap-based buffer oob read. In cases where ASAN is enabled while compiling this causes a crash. Further info leak or more damage is possible.

CVSS3: 7.1
0%
Низкий
больше 2 лет назад
redhat логотип
CVE-2023-2977

A vulnerbility was found in OpenSC. This security flaw cause a buffer overrun vulnerability in pkcs15 cardos_have_verifyrc_package. The attacker can supply a smart card package with malformed ASN1 context. The cardos_have_verifyrc_package function scans the ASN1 buffer for 2 tags, where remaining length is wrongly caculated due to moved starting pointer. This leads to possible heap-based buffer oob read. In cases where ASAN is enabled while compiling this causes a crash. Further info leak or more damage is possible.

CVSS3: 6.3
0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-2977

A vulnerbility was found in OpenSC. This security flaw cause a buffer overrun vulnerability in pkcs15 cardos_have_verifyrc_package. The attacker can supply a smart card package with malformed ASN1 context. The cardos_have_verifyrc_package function scans the ASN1 buffer for 2 tags, where remaining length is wrongly caculated due to moved starting pointer. This leads to possible heap-based buffer oob read. In cases where ASAN is enabled while compiling this causes a crash. Further info leak or more damage is possible.

CVSS3: 7.1
0%
Низкий
больше 2 лет назад
msrc логотип
CVSS3: 7.1
0%
Низкий
около 2 лет назад
debian логотип
CVE-2023-2977

A vulnerbility was found in OpenSC. This security flaw cause a buffer ...

CVSS3: 7.1
0%
Низкий
больше 2 лет назад
suse-cvrf логотип
SUSE-SU-2023:2516-1

Security update for opensc

0%
Низкий
около 2 лет назад
suse-cvrf логотип
SUSE-SU-2023:2508-1

Security update for opensc

0%
Низкий
около 2 лет назад
suse-cvrf логотип
SUSE-SU-2023:2466-1

Security update for opensc

0%
Низкий
около 2 лет назад
github логотип
GHSA-p22r-5f28-437x

A vulnerbility was found in OpenSC. This security flaw cause a buffer overrun vulnerability in pkcs15 cardos_have_verifyrc_package. The attacker can supply a smart card package with malformed ASN1 context. The cardos_have_verifyrc_package function scans the ASN1 buffer for 2 tags, where remaining length is wrongly caculated due to moved starting pointer. This leads to possible heap-based buffer oob read. In cases where ASAN is enabled while compiling this causes a crash. Further info leak or more damage is possible.

CVSS3: 7.1
0%
Низкий
больше 2 лет назад
oracle-oval логотип
ELSA-2023-7160

ELSA-2023-7160: opensc security and bug fix update (LOW)

почти 2 года назад
oracle-oval логотип
ELSA-2023-6587

ELSA-2023-6587: opensc security update (LOW)

почти 2 года назад

Уязвимостей на страницу