CVE-2010-4523

Multiple stack-based buffer overflows in libopensc in OpenSC 0.11.13 and earlier allow physically proximate attackers to execute arbitrary code via a long serial-number field on a smart card, related to (1) card-acos5.c, (2) card-atrust-acos.c, and (3) card-starcos.c.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.2 UNKNOWN
LOCAL
LOW
AV:L/AC:L/Au:N/C:C/I:C/A:C
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 49%
VendorProductVersion
opensc-projectopensc
𝑥
≤ 0.11.13
opensc-projectopensc
0.3.2
opensc-projectopensc
0.3.5
opensc-projectopensc
0.4.0
opensc-projectopensc
0.5.0
opensc-projectopensc
0.6.0
opensc-projectopensc
0.6.1
opensc-projectopensc
0.7.0
opensc-projectopensc
0.8
opensc-projectopensc
0.8.0
opensc-projectopensc
0.8.0.0
opensc-projectopensc
0.8.1
opensc-projectopensc
0.9
opensc-projectopensc
0.9.2
opensc-projectopensc
0.9.3
opensc-projectopensc
0.9.4
opensc-projectopensc
0.9.5
opensc-projectopensc
0.9.6
opensc-projectopensc
0.9.7
opensc-projectopensc
0.9.7:b
opensc-projectopensc
0.9.7:d
opensc-projectopensc
0.9.8
opensc-projectopensc
0.10.0
opensc-projectopensc
0.10.1
opensc-projectopensc
0.11.0
opensc-projectopensc
0.11.1
opensc-projectopensc
0.11.2
opensc-projectopensc
0.11.3
opensc-projectopensc
0.11.3:pre3
opensc-projectopensc
0.11.4
opensc-projectopensc
0.11.5
opensc-projectopensc
0.11.6
opensc-projectopensc
0.11.7
opensc-projectopensc
0.11.8
opensc-projectopensc
0.11.9
opensc-projectopensc
0.11.10
opensc-projectopensc
0.11.11
opensc-projectopensc
0.11.12
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
opensc
bullseye
0.21.0-1
fixed
bookworm
0.23.0-0.3+deb12u1
fixed
sid
0.25.1-2
fixed
trixie
0.25.1-2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
opensc
maverick
Fixed 0.11.13-1ubuntu2.1
released
lucid
Fixed 0.11.12-1ubuntu3.2
released
karmic
Fixed 0.11.8-1ubuntu2.1
released
hardy
Fixed 0.11.4-2ubuntu2.1
released
dapper
ignored
References