CVE-2009-1603Cleartext Storage of Sensitive Info in Opensc

Severity
7.5HIGHNVD
EPSS
1.1%
top 22.43%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 11
Latest updateMay 2

Description

src/tools/pkcs11-tool.c in pkcs11-tool in OpenSC 0.11.7, when used with unspecified third-party PKCS#11 modules, generates RSA keys with incorrect public exponents, which allows attackers to read the cleartext form of messages that were intended to be encrypted.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages2 packages

Debianopensc_project/opensc< 0.11.8+3

Also affects: Fedora 10, 11, 9

Patches

🔴Vulnerability Details

3
GHSA
GHSA-8772-675x-8fvx: src/tools/pkcs11-tool2022-05-02
OSV
CVE-2009-1603: src/tools/pkcs11-tool2009-05-11
CVEList
CVE-2009-1603: src/tools/pkcs11-tool2009-05-11

📋Vendor Advisories

2
Red Hat
opensc: insecure public exponent in opensc 0.11.72009-05-08
Debian
CVE-2009-1603: opensc - src/tools/pkcs11-tool.c in pkcs11-tool in OpenSC 0.11.7, when used with unspecif...2009

💬Community

1
Bugzilla
CVE-2009-1603 opensc: insecure public exponent in opensc 0.11.72009-05-08
CVE-2009-1603 — Cleartext Storage of Sensitive Info | cvebase