Opensc: out-of-bounds read in myeid driver handling encryption using symmetric keys
Published Nov 6, 2023
4.5
MEDIUMCVSS 3.1
EPSS 0.52%
Description
An out-of-bounds read vulnerability was found in OpenSC packages within the MyEID driver when handling symmetric key encryption. Exploiting this flaw requires an attacker to have physical access to the computer and a specially crafted USB device or smart card. This flaw allows the attacker to manipulate APDU responses and potentially gain unauthorized access to sensitive data, compromising the system's security.
Affected products
No data.
Configuration 1
- 0.23.0
- 0.23.0
- 0.23.0
Configuration 2
- 38
- 39
- 9.0
No data.
Red Hat Enterprise Linux 9
opensc-0:0.23.0-3.el9_3
Fixed · RHSA-2023:7879
Red Hat Enterprise Linux 7
opensc
Not affected
Red Hat Enterprise Linux 8
opensc
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 9 | opensc-0:0.23.0-3.el9_3 | Fixed | RHSA-2023:7879 |
| Red Hat Enterprise Linux 7 | opensc | Not affected | n/a |
| Red Hat Enterprise Linux 8 | opensc | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This CVE does not affect Red Hat Enterprise Linux 8 as the affected functionality was introduced in OpenSC-0.23.0 and RHEL-8 uses OpenSC-0.20.0 and lower versions.
References (12)
- https://access.redhat.com/errata/RHSA-2023:7879 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2023-4535 vdb-entryx_refsource_REDHATThird Party AdvisoryVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2240914 issue-trackingx_refsource_REDHATIssue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-54390 Advisory
- https://github.com/OpenSC/OpenSC/commit/f1993dc4e0b33050b8f72a3558ee88b24c4063b2 Patch
- https://github.com/OpenSC/OpenSC/issues/2792#issuecomment-1674806651 Issue TrackingPatch
- https://github.com/OpenSC/OpenSC/releases/tag/0.24.0-rc1 Release Notes
- https://github.com/OpenSC/OpenSC/wiki/OpenSC-security-advisories Vendor Advisory
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3CPQOMCDWFRBMEFR5VK4N5MMXXU42ODE/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GLYEFIBBA37TK3UNMZN5NOJ7IWCIXLQP/
- https://nvd.nist.gov/vuln/detail/CVE-2023-4535
- https://www.cve.org/CVERecord?id=CVE-2023-4535
Change history (0)
No recorded changes yet.