opensc: buffer overrun vulnerability in pkcs15 cardos_have_verifyrc_package
Published Jun 1, 2023
7.1
HIGHCVSS 3.1
EPSS 0.29%
Description
A vulnerbility was found in OpenSC. This security flaw cause a buffer overrun vulnerability in pkcs15 cardos_have_verifyrc_package. The attacker can supply a smart card package with malformed ASN1 context. The cardos_have_verifyrc_package function scans the ASN1 buffer for 2 tags, where remaining length is wrongly caculated due to moved starting pointer. This leads to possible heap-based buffer oob read. In cases where ASAN is enabled while compiling this causes a crash. Further info leak or more damage is possible.
Affected products
- Vendor n/a Product OpenSC Defaultunknown
Affected
- opensc-0.23.0
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| n/a | OpenSC | unknown | Affected
|
Configuration 1
- 0.23.0
Configuration 2
- 8.0
- 9.0
No data.
Red Hat Enterprise Linux 8
opensc-0:0.20.0-6.el8
Fixed · RHSA-2023:7160
Red Hat Enterprise Linux 9
opensc-0:0.23.0-2.el9
Fixed · RHSA-2023:6587
Red Hat Enterprise Linux 7
opensc
Out of support scope
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | opensc-0:0.20.0-6.el8 | Fixed | RHSA-2023:7160 |
| Red Hat Enterprise Linux 9 | opensc-0:0.23.0-2.el9 | Fixed | RHSA-2023:6587 |
| Red Hat Enterprise Linux 7 | opensc | Out of support scope | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (11)
- https://access.redhat.com/security/cve/CVE-2023-2977 Third Party AdvisoryVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2211088 Issue TrackingThird Party Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-34418 Advisory
- https://github.com/OpenSC/OpenSC/issues/2785 Issue TrackingPatch
- https://github.com/OpenSC/OpenSC/pull/2787 Patch
- https://lists.debian.org/debian-lts-announce/2023/06/msg00025.html mailing-list
- https://lists.debian.org/debian-lts-announce/2024/12/msg00026.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FJD4Q4AJSGE5UIJI7OUYZY4HGGCVYQNI/ vendor-advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LAR54OV6EHA56B4XJF6RNPQ4HJ2ITU66/ vendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2023-2977
- https://www.cve.org/CVERecord?id=CVE-2023-2977
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
GitHub
No data