CVSS2
Attack Vector
LOCAL
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
NONE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
AV:L/AC:L/Au:N/C:N/I:C/A:C
AI Score
Confidence
Low
EPSS
Percentile
26.7%
pkcs15-tool in OpenSC before 0.11.6 does not apply security updates to a smart card unless the cardโs label matches the โOpenSCโ string, which might allow physically proximate attackers to exploit vulnerabilities that the card owner expected were patched, as demonstrated by exploitation of CVE-2008-2235.
Vendor | Product | Version | CPE |
---|---|---|---|
opensc-project | opensc | * | cpe:2.3:a:opensc-project:opensc:*:*:*:*:*:*:*:* |
opensc-project | opensc | 0.4.0 | cpe:2.3:a:opensc-project:opensc:0.4.0:*:*:*:*:*:*:* |
opensc-project | opensc | 0.5.0 | cpe:2.3:a:opensc-project:opensc:0.5.0:*:*:*:*:*:*:* |
opensc-project | opensc | 0.6.0 | cpe:2.3:a:opensc-project:opensc:0.6.0:*:*:*:*:*:*:* |
opensc-project | opensc | 0.6.1 | cpe:2.3:a:opensc-project:opensc:0.6.1:*:*:*:*:*:*:* |
opensc-project | opensc | 0.7.0 | cpe:2.3:a:opensc-project:opensc:0.7.0:*:*:*:*:*:*:* |
opensc-project | opensc | 0.8.0 | cpe:2.3:a:opensc-project:opensc:0.8.0:*:*:*:*:*:*:* |
opensc-project | opensc | 0.8.1 | cpe:2.3:a:opensc-project:opensc:0.8.1:*:*:*:*:*:*:* |
opensc-project | opensc | 0.9.2 | cpe:2.3:a:opensc-project:opensc:0.9.2:*:*:*:*:*:*:* |
opensc-project | opensc | 0.9.3 | cpe:2.3:a:opensc-project:opensc:0.9.3:*:*:*:*:*:*:* |
lists.opensuse.org/opensuse-security-announce/2008-09/msg00005.html
secunia.com/advisories/32099
secunia.com/advisories/34362
www.opensc-project.org/pipermail/opensc-announce/2008-August/000021.html
www.openwall.com/lists/oss-security/2008/09/09/14
exchange.xforce.ibmcloud.com/vulnerabilities/45045
www.redhat.com/archives/fedora-package-announce/2009-March/msg00686.html
More