cbcvebase.
CVE-2023-4535
published 2023-11-06

CVE-2023-4535: An out-of-bounds read vulnerability was found in OpenSC packages within the MyEID driver when handling symmetric key encryption. Exploiting this flaw requires…

low3.8CVSS 3.1
AVPACHPRNUIRSUCLILAL
An out-of-bounds read vulnerability was found in OpenSC packages within the MyEID driver when handling symmetric key encryption. Exploiting this flaw requires an attacker to have physical access to the computer and a specially crafted USB device or smart card. This flaw allows the attacker to manipulate APDU responses and potentially gain unauthorized access to sensitive data, compromising the system's security.

Affected

15 ranges
VendorProductVersion rangeFixed in
debianopensc< opensc 0.23.0-0.3+deb12u1 (bookworm)opensc 0.23.0-0.3+deb12u1 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
msrcazl3_opensc_0.23.0-1_on_azure_linux_3.0
msrcazl3_opensc_0.25.1-3_on_azure_linux_3.0
msrcazure_linux_3.0_arm
msrcazure_linux_3.0_x64
msrccbl2_opensc_0.23.0-2_on_cbl_mariner_2.0
msrccbl_mariner_2.0_arm
msrccbl_mariner_2.0_x64
opensc_projectopensc
opensc_projectopensc>= 0 < 0.23.0-0.3+deb12u10.23.0-0.3+deb12u1
opensc_projectopensc>= 0 < 0.23.0-20.23.0-2
opensc_projectopensc>= 0 < 0.23.0-20.23.0-2
redhatenterprise_linux

CVSS provenance

nvdv3.13.8LOWCVSS:3.1/AV:P/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L
osv3.8LOW