CVE-2023-2977

CVSS V2 None CVSS V3 None
Description
A vulnerbility was found in OpenSC. This security flaw cause a buffer overrun vulnerability in pkcs15 cardos_have_verifyrc_package. The attacker can supply a smart card package with malformed ASN1 context. The cardos_have_verifyrc_package function scans the ASN1 buffer for 2 tags, where remaining length is wrongly caculated due to moved starting pointer. This leads to possible heap-based buffer oob read. In cases where ASAN is enabled while compiling this causes a crash. Further info leak or more damage is possible.
Overview
  • CVE ID
  • CVE-2023-2977
  • Assigner
  • redhat
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2023-06-01T00:00:00
  • Last Modified Date
  • 2023-08-17T18:06:58.134977
History
Created Old Value New Value Data Type Notes
2024-06-24 21:48:11 Added to TrackCVE