CVE-2010-4523Improper Restriction of Operations within the Bounds of a Memory Buffer in Opensc

Severity
7.2HIGHNVD
EPSS
0.3%
top 50.39%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 7
Latest updateMay 17

Description

Multiple stack-based buffer overflows in libopensc in OpenSC 0.11.13 and earlier allow physically proximate attackers to execute arbitrary code via a long serial-number field on a smart card, related to (1) card-acos5.c, (2) card-atrust-acos.c, and (3) card-starcos.c.

CVSS vector

AV:L/AC:L/C:C/I:C/A:CExploitability: 3.9 | Impact: 10.0

Affected Packages2 packages

Debianopensc_project/opensc< 0.11.13-1.1+3
NVDopensc-project/opensc0.11.13+34

Patches

🔴Vulnerability Details

3
GHSA
GHSA-8q7x-x6wm-6x5q: Multiple stack-based buffer overflows in libopensc in OpenSC 02022-05-17
OSV
CVE-2010-4523: Multiple stack-based buffer overflows in libopensc in OpenSC 02011-01-07
CVEList
CVE-2010-4523: Multiple stack-based buffer overflows in libopensc in OpenSC 02011-01-07

📋Vendor Advisories

1
Debian
CVE-2010-4523: opensc - Multiple stack-based buffer overflows in libopensc in OpenSC 0.11.13 and earlier...2010

💬Community

1
Bugzilla
CVE-2010-4523 OpenSC: Three stack-based buffer overflows, when processing crafted serial numbers of certain cards2010-12-21
CVE-2010-4523 — Opensc-project Opensc vulnerability | cvebase