CVE-2010-4523
published 2011-01-07CVE-2010-4523: Multiple stack-based buffer overflows in libopensc in OpenSC 0.11.13 and earlier allow physically proximate attackers to execute arbitrary code via a long…
PriorityP433high7.2CVSS 2.0
AVLACLAuNCCICAC
EPSS
0.86%
54.7th percentile
Multiple stack-based buffer overflows in libopensc in OpenSC 0.11.13 and earlier allow physically proximate attackers to execute arbitrary code via a long serial-number field on a smart card, related to (1) card-acos5.c, (2) card-atrust-acos.c, and (3) card-starcos.c.
Affected
40 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | opensc | < opensc 0.11.13-1.1 (bookworm) | opensc 0.11.13-1.1 (bookworm) |
| opensc-project | opensc | <= 0.11.13 | — |
| opensc-project | opensc | — | — |
| opensc-project | opensc | — | — |
| opensc-project | opensc | — | — |
| opensc-project | opensc | — | — |
| opensc-project | opensc | — | — |
| opensc-project | opensc | — | — |
| opensc-project | opensc | — | — |
| opensc-project | opensc | — | — |
| opensc-project | opensc | — | — |
| opensc-project | opensc | — | — |
| opensc-project | opensc | — | — |
| opensc-project | opensc | — | — |
| opensc-project | opensc | — | — |
| opensc-project | opensc | — | — |
| opensc-project | opensc | — | — |
| opensc-project | opensc | — | — |
| opensc-project | opensc | — | — |
| opensc-project | opensc | — | — |
| opensc-project | opensc | — | — |
| opensc-project | opensc | — | — |
| opensc-project | opensc | — | — |
| opensc-project | opensc | — | — |
| opensc-project | opensc | — | — |
CVSS provenance
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.2HIGH
vendor_debian7.2LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-8q7x-x6wm-6x5q: Multiple stack-based buffer overflows in libopensc in OpenSC 0
ghsa_unreviewed·2022-05-17
CVE-2010-4523 [HIGH] CWE-119 GHSA-8q7x-x6wm-6x5q: Multiple stack-based buffer overflows in libopensc in OpenSC 0
Multiple stack-based buffer overflows in libopensc in OpenSC 0.11.13 and earlier allow physically proximate attackers to execute arbitrary code via a long serial-number field on a smart card, related to (1) card-acos5.c, (2) card-atrust-acos.c, and (3) card-starcos.c.
OSV
CVE-2010-4523: Multiple stack-based buffer overflows in libopensc in OpenSC 0
osv·2011-01-07·CVSS 7.2
CVE-2010-4523 [HIGH] CVE-2010-4523: Multiple stack-based buffer overflows in libopensc in OpenSC 0
Multiple stack-based buffer overflows in libopensc in OpenSC 0.11.13 and earlier allow physically proximate attackers to execute arbitrary code via a long serial-number field on a smart card, related to (1) card-acos5.c, (2) card-atrust-acos.c, and (3) card-starcos.c.
Debian
CVE-2010-4523: opensc - Multiple stack-based buffer overflows in libopensc in OpenSC 0.11.13 and earlier...
vendor_debian·2010·CVSS 7.2
CVE-2010-4523 [HIGH] CVE-2010-4523: opensc - Multiple stack-based buffer overflows in libopensc in OpenSC 0.11.13 and earlier...
Multiple stack-based buffer overflows in libopensc in OpenSC 0.11.13 and earlier allow physically proximate attackers to execute arbitrary code via a long serial-number field on a smart card, related to (1) card-acos5.c, (2) card-atrust-acos.c, and (3) card-starcos.c.
Scope: local
bookworm: resolved (fixed in 0.11.13-1.1)
bullseye: resolved (fixed in 0.11.13-1.1)
forky: resolved (fixed in 0.11.13-1.1)
sid: resolved (fixed in 0.11.13-1.1)
trixie: resolved (fixed in 0.11.13-1.1)
No detection rules found.
No public exploits indexed.
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=607427http://labs.mwrinfosecurity.com/files/Advisories/mwri_opensc-get-serial-buffer-overflow_2010-12-13.pdfhttp://lists.fedoraproject.org/pipermail/package-announce/2011-January/052777.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-January/052796.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.htmlhttp://openwall.com/lists/oss-security/2010/12/21/2http://openwall.com/lists/oss-security/2010/12/22/3http://secunia.com/advisories/42658http://secunia.com/advisories/42807http://secunia.com/advisories/43068http://www.h-online.com/open/news/item/When-a-smart-card-can-root-your-computer-1154829.htmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2011:011http://www.securityfocus.com/bid/45435http://www.vupen.com/english/advisories/2011/0009http://www.vupen.com/english/advisories/2011/0109http://www.vupen.com/english/advisories/2011/0212https://bugs.launchpad.net/ubuntu/+source/opensc/+bug/692483https://bugzilla.redhat.com/show_bug.cgi?id=664831https://www.opensc-project.org/opensc/changeset/4913http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=607427http://labs.mwrinfosecurity.com/files/Advisories/mwri_opensc-get-serial-buffer-overflow_2010-12-13.pdfhttp://lists.fedoraproject.org/pipermail/package-announce/2011-January/052777.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-January/052796.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.htmlhttp://openwall.com/lists/oss-security/2010/12/21/2http://openwall.com/lists/oss-security/2010/12/22/3http://secunia.com/advisories/42658http://secunia.com/advisories/42807http://secunia.com/advisories/43068http://www.h-online.com/open/news/item/When-a-smart-card-can-root-your-computer-1154829.htmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2011:011http://www.securityfocus.com/bid/45435http://www.vupen.com/english/advisories/2011/0009http://www.vupen.com/english/advisories/2011/0109http://www.vupen.com/english/advisories/2011/0212https://bugs.launchpad.net/ubuntu/+source/opensc/+bug/692483https://bugzilla.redhat.com/show_bug.cgi?id=664831https://www.opensc-project.org/opensc/changeset/4913
2011-01-07
Published