Description
A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK.
The problem is missing initialization of variables expected to be initialized (as arguments to other functions, etc.).
CVSS vector
CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:LExploitability: 0.5 | Impact: 3.4Attack Vector: Physical
Complexity: High
Privileges: None
User Interaction: None
Scope: Unchanged
Confidentiality: Low
Integrity: Low
Availability: Low
Affected Packages2 packages
Also affects: Enterprise Linux 7.0, 8.0, 9.0
🔴Vulnerability Details
3GHSAGHSA-3q68-hm47-94vg: A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK↗2024-09-04 ▶ OSVCVE-2024-45615: A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK↗2024-09-03 ▶ CVEListLibopensc: pkcs15init: usage of uninitialized values in libopensc and pkcs15init↗2024-09-03 ▶ 📋Vendor Advisories
4UbuntuOpenSC vulnerabilities↗2025-04-09 ▶ UbuntuOpenSC vulnerabilities↗2025-03-12 ▶ Red Hatlibopensc: pkcs15init: Usage of uninitialized values in libopensc and pkcs15init↗2024-09-02 ▶ DebianCVE-2024-45615: opensc - A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, a...↗2024 ▶