CVE-2023-4535Out-of-bounds Read in Project Opensc

CWE-125Out-of-bounds Read7 documents7 sources
Severity
3.8LOWNVD
CNA4.5
EPSS
0.2%
top 54.18%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 6
Latest updateNov 14

Description

An out-of-bounds read vulnerability was found in OpenSC packages within the MyEID driver when handling symmetric key encryption. Exploiting this flaw requires an attacker to have physical access to the computer and a specially crafted USB device or smart card. This flaw allows the attacker to manipulate APDU responses and potentially gain unauthorized access to sensitive data, compromising the system's security.

CVSS vector

CVSS:3.1/AV:P/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:LExploitability: 0.4 | Impact: 3.4

Affected Packages2 packages

Debianopensc_project/opensc< 0.23.0-0.3+deb12u1+2

Also affects: Fedora 38, 39, Enterprise Linux 9.0

Patches

🔴Vulnerability Details

3
OSV
CVE-2023-4535: An out-of-bounds read vulnerability was found in OpenSC packages within the MyEID driver when handling symmetric key encryption2023-11-06
GHSA
GHSA-phh2-j3h6-vqr9: An out-of-bounds read vulnerability was found in OpenSC packages within the MyEID driver when handling symmetric key encryption2023-11-06
CVEList
Opensc: out-of-bounds read in myeid driver handling encryption using symmetric keys2023-11-06

📋Vendor Advisories

3
Microsoft
Opensc: out-of-bounds read in myeid driver handling encryption using symmetric keys2023-11-14
Red Hat
OpenSC: out-of-bounds read in MyEID driver handling encryption using symmetric keys2023-09-25
Debian
CVE-2023-4535: opensc - An out-of-bounds read vulnerability was found in OpenSC packages within the MyEI...2023
CVE-2023-4535 — Out-of-bounds Read in Project Opensc | cvebase