CVE-2008-2235Code Injection in Opensc

Severity
4.9MEDIUMNVD
GHSA9.0
EPSS
0.1%
top 79.17%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 1
Latest updateMay 17

Description

OpenSC before 0.11.5 uses weak permissions (ADMIN file control information of 00) for the 5015 directory on smart cards and USB crypto tokens running Siemens CardOS M4, which allows physically proximate attackers to change the PIN.

CVSS vector

AV:L/AC:L/C:N/I:C/A:NExploitability: 3.9 | Impact: 6.9

Affected Packages2 packages

Debianopensc_project/opensc< 0.11.4-4+3
NVDopensc-project/opensc18 versions+17

Patches

🔴Vulnerability Details

4
GHSA
Cobbler is vulnerable to code injection2022-05-17
GHSA
GHSA-8cph-r8x9-fxx9: OpenSC before 02022-05-01
CVEList
CVE-2008-2235: OpenSC before 02008-08-01
OSV
CVE-2008-2235: OpenSC before 02008-08-01

📋Vendor Advisories

3
Red Hat
(cobbler): Code injection flaw (ACE as root) by processing of a specially-crafted kickstart template file2010-10-18
Red Hat
opensc: incorrect initialization of Siemens CardOS M4 smart cards2008-07-31
Debian
CVE-2008-2235: opensc - OpenSC before 0.11.5 uses weak permissions (ADMIN file control information of 00...2008

💬Community

1
Bugzilla
CVE-2008-2235, CVE-2008-3972 opensc: incorrect initialization of Siemens CardOS M4 smart cards2008-07-31
CVE-2008-2235 — Code Injection in Opensc-project Opensc | cvebase