CVE-2023-2977
CVSS V2 None
CVSS V3 None
Description
A vulnerbility was found in OpenSC. This security flaw cause a buffer overrun vulnerability in pkcs15 cardos_have_verifyrc_package. The attacker can supply a smart card package with malformed ASN1 context. The cardos_have_verifyrc_package function scans the ASN1 buffer for 2 tags, where remaining length is wrongly caculated due to moved starting pointer. This leads to possible heap-based buffer oob read. In cases where ASAN is enabled while compiling this causes a crash. Further info leak or more damage is possible.
Overview
- CVE ID
- CVE-2023-2977
- Assigner
- redhat
- Vulnerability Status
- PUBLISHED
- Published Version
- 2023-06-01T00:00:00
- Last Modified Date
- 2023-08-17T18:06:58.134977
Weakness Enumerations
References
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2023-2977 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-2977 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2024-06-24 21:48:11 | Added to TrackCVE |