Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:43570
HistoryOct 06, 2023 - 12:09 p.m.

Out-of-bounds Read

2023-10-0612:09:10
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
7
vulnerability
out-of-bounds read
libopensc.so
card-myeid.c
symmetric keys
maliciously crafted responses
apdu
information security

4.5 Medium

CVSS3

Attack Vector

PHYSICAL

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:P/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:L

0.001 Low

EPSS

Percentile

25.1%

libopensc.so is vulnerable to out-of-bounds reads. The vulnerability exists in card-myeid.c because it does not properly validate symmetric keys, which allows an attacker to send maliciously crafted responses to the APDU and read information outside of the intended range.

4.5 Medium

CVSS3

Attack Vector

PHYSICAL

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:P/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:L

0.001 Low

EPSS

Percentile

25.1%