CVSS3
Attack Vector
PHYSICAL
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality Impact
LOW
Integrity Impact
LOW
Availability Impact
NONE
CVSS:3.1/AV:P/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N
AI Score
Confidence
High
EPSS
Percentile
13.4%
A heap-based buffer overflow vulnerability was found in the libopensc OpenPGP driver. A crafted USB device or smart card with malicious responses to the APDUs during the card enrollment process using the pkcs15-init
tool may lead to out-of-bound rights, possibly resulting in arbitrary code execution.
OS | Version | Architecture | Package | Version | Filename |
---|---|---|---|---|---|
Debian | 12 | all | opensc | <= 0.23.0-0.3+deb12u1 | opensc_0.23.0-0.3+deb12u1_all.deb |
Debian | 11 | all | opensc | <= 0.21.0-1 | opensc_0.21.0-1_all.deb |
Debian | 999 | all | opensc | <= 0.25.1-2 | opensc_0.25.1-2_all.deb |
Debian | 13 | all | opensc | <= 0.25.1-2 | opensc_0.25.1-2_all.deb |
CVSS3
Attack Vector
PHYSICAL
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality Impact
LOW
Integrity Impact
LOW
Availability Impact
NONE
CVSS:3.1/AV:P/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N
AI Score
Confidence
High
EPSS
Percentile
13.4%