CVE-2010-4523 — Improper Restriction of Operations within the Bounds of a Memory Buffer in Opensc
Severity
7.2HIGHNVD
EPSS
0.3%
top 50.39%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 7
Latest updateMay 17
Description
Multiple stack-based buffer overflows in libopensc in OpenSC 0.11.13 and earlier allow physically proximate attackers to execute arbitrary code via a long serial-number field on a smart card, related to (1) card-acos5.c, (2) card-atrust-acos.c, and (3) card-starcos.c.
CVSS vector
AV:L/AC:L/C:C/I:C/A:CExploitability: 3.9 | Impact: 10.0
Affected Packages2 packages
Patches
🔴Vulnerability Details
3📋Vendor Advisories
1Debian▶
CVE-2010-4523: opensc - Multiple stack-based buffer overflows in libopensc in OpenSC 0.11.13 and earlier...↗2010
💬Community
1Bugzilla▶
CVE-2010-4523 OpenSC: Three stack-based buffer overflows, when processing crafted serial numbers of certain cards↗2010-12-21