CVE-2009-1603

EUVD-2009-1598
src/tools/pkcs11-tool.c in pkcs11-tool in OpenSC 0.11.7, when used with unspecified third-party PKCS#11 modules, generates RSA keys with incorrect public exponents, which allows attackers to read the cleartext form of messages that were intended to be encrypted.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 77%
Affected Products (NVD)
VendorProductVersion
opensc-projectopensc
0.11.7
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
opensc
bookworm
0.23.0-0.3+deb12u1
fixed
bullseye
0.21.0-1
fixed
etch
not-affected
lenny
not-affected
sid
0.25.1-2
fixed
trixie
0.25.1-2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
opensc
dapper
not-affected
hardy
not-affected
intrepid
not-affected
jaunty
not-affected
karmic
ignored
lucid
not-affected
maverick
not-affected
natty
not-affected
References