CVE-2021-34193Out-of-bounds Write in Project Opensc

Severity
7.5HIGHNVD
EPSS
0.5%
top 33.12%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 22

Description

Stack overflow vulnerability in OpenSC smart card middleware before 0.23 via crafted responses to APDUs.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages2 packages

NVDopensc_project/opensc< 0.22.0
Debianopensc_project/opensc< 0.21.0-1+deb11u1+3

🔴Vulnerability Details

3
GHSA
GHSA-882v-v6g5-f7qr: Stack overflow vulnerability in OpenSC smart card middleware before 02023-08-22
OSV
CVE-2021-34193: Stack overflow vulnerability in OpenSC smart card middleware before 02023-08-22
CVEList
CVE-2021-34193: Stack overflow vulnerability in OpenSC smart card middleware before 02023-08-22

📋Vendor Advisories

3
Red Hat
opensc: Stack overflow vulnerability in OpenSC smart card middleware2023-08-22
Microsoft
Stack overflow vulnerability in OpenSC smart card middleware before 0.23 via crafted responses to APDUs.2023-08-08
Debian
CVE-2021-34193: opensc - Stack overflow vulnerability in OpenSC smart card middleware before 0.23 via cra...2021
CVE-2021-34193 — Out-of-bounds Write in Project Opensc | cvebase