Untriaged
Permalink
CVE-2023-40661
5.4 MEDIUM
- CVSS version: 3.1
- Attack vector (AV): PHYSICAL
- Attack complexity (AC): LOW
- Privileges required (PR): NONE
- User interaction (UI): REQUIRED
- Scope (S): UNCHANGED
- Confidentiality impact (C): LOW
- Integrity impact (I): LOW
- Availability impact (A): HIGH
Opensc: multiple memory issues with pkcs15-init (enrollment tool)
Several memory vulnerabilities were identified within the OpenSC packages, particularly in the card enrollment process using pkcs15-init when a user or administrator enrolls cards. To take advantage of these flaws, an attacker must have physical access to the computer system and employ a custom-crafted USB device or smart card to manipulate responses to APDUs. This manipulation can potentially allow compromise key generation, certificate loading, and other card management operations during enrollment.
References
- http://www.openwall.com/lists/oss-security/2023/12/13/3
- RHSA-2023:7876 x_refsource_REDHAT vendor-advisory
- RHSA-2023:7879 x_refsource_REDHAT vendor-advisory
- https://access.redhat.com/security/cve/CVE-2023-40661 x_refsource_REDHAT vdb-entry
- RHBZ#2240913 issue-tracking x_refsource_REDHAT
- https://github.com/OpenSC/OpenSC/issues/2792#issuecomment-1674806651
- https://github.com/OpenSC/OpenSC/releases/tag/0.24.0-rc1
- https://github.com/OpenSC/OpenSC/wiki/OpenSC-security-advisories
- https://lists.debian.org/debian-lts-announce/2023/11/msg00024.html
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj…
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj…
- http://www.openwall.com/lists/oss-security/2023/12/13/3
- RHSA-2023:7876 x_refsource_REDHAT vendor-advisory
- RHSA-2023:7879 x_refsource_REDHAT vendor-advisory
- https://access.redhat.com/security/cve/CVE-2023-40661 x_refsource_REDHAT vdb-entry
- RHBZ#2240913 issue-tracking x_refsource_REDHAT
- https://github.com/OpenSC/OpenSC/issues/2792#issuecomment-1674806651
- https://github.com/OpenSC/OpenSC/releases/tag/0.24.0-rc1
- https://github.com/OpenSC/OpenSC/wiki/OpenSC-security-advisories
- https://lists.debian.org/debian-lts-announce/2023/11/msg00024.html
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj…
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj…
- http://www.openwall.com/lists/oss-security/2023/12/13/3
- RHSA-2023:7876 x_refsource_REDHAT vendor-advisory
- RHSA-2023:7879 x_refsource_REDHAT vendor-advisory
- https://access.redhat.com/security/cve/CVE-2023-40661 x_refsource_REDHAT vdb-entry
- RHBZ#2240913 issue-tracking x_refsource_REDHAT
- https://github.com/OpenSC/OpenSC/issues/2792#issuecomment-1674806651
- https://github.com/OpenSC/OpenSC/releases/tag/0.24.0-rc1
- https://github.com/OpenSC/OpenSC/wiki/OpenSC-security-advisories
- https://lists.debian.org/debian-lts-announce/2023/11/msg00024.html
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj…
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj…
- RHSA-2023:7876 x_refsource_REDHAT vendor-advisory
- RHSA-2023:7879 x_refsource_REDHAT vendor-advisory
- https://access.redhat.com/security/cve/CVE-2023-40661 x_refsource_REDHAT vdb-entry
- RHBZ#2240913 issue-tracking x_refsource_REDHAT
- https://github.com/OpenSC/OpenSC/issues/2792#issuecomment-1674806651
- https://github.com/OpenSC/OpenSC/releases/tag/0.24.0-rc1
- https://github.com/OpenSC/OpenSC/wiki/OpenSC-security-advisories
- https://lists.debian.org/debian-lts-announce/2023/11/msg00024.html
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj…
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj…
- http://www.openwall.com/lists/oss-security/2023/12/13/3
- http://www.openwall.com/lists/oss-security/2023/12/13/3 x_transferred
- RHSA-2023:7876 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2023:7879 x_refsource_REDHAT vendor-advisory x_transferred
- https://access.redhat.com/security/cve/CVE-2023-40661 x_refsource_REDHAT vdb-entry x_transferred
- RHBZ#2240913 issue-tracking x_refsource_REDHAT x_transferred
- https://github.com/OpenSC/OpenSC/issues/2792#issuecomment-1674806651 x_transferred
- https://github.com/OpenSC/OpenSC/releases/tag/0.24.0-rc1 x_transferred
- https://github.com/OpenSC/OpenSC/wiki/OpenSC-security-advisories x_transferred
- https://lists.debian.org/debian-lts-announce/2023/11/msg00024.html x_transferred
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj… x_transferred
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj… x_transferred
- http://www.openwall.com/lists/oss-security/2023/12/13/3
- RHSA-2023:7876 x_refsource_REDHAT vendor-advisory
- RHSA-2023:7879 x_refsource_REDHAT vendor-advisory
- https://access.redhat.com/security/cve/CVE-2023-40661 x_refsource_REDHAT vdb-entry
- RHBZ#2240913 issue-tracking x_refsource_REDHAT
- https://github.com/OpenSC/OpenSC/issues/2792#issuecomment-1674806651
- https://github.com/OpenSC/OpenSC/releases/tag/0.24.0-rc1
- https://github.com/OpenSC/OpenSC/wiki/OpenSC-security-advisories
- https://lists.debian.org/debian-lts-announce/2023/11/msg00024.html
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj…
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj…
- http://www.openwall.com/lists/oss-security/2023/12/13/3 x_transferred
- RHSA-2023:7876 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2023:7879 x_refsource_REDHAT vendor-advisory x_transferred
- https://access.redhat.com/security/cve/CVE-2023-40661 x_refsource_REDHAT vdb-entry x_transferred
- RHBZ#2240913 issue-tracking x_refsource_REDHAT x_transferred
- https://github.com/OpenSC/OpenSC/issues/2792#issuecomment-1674806651 x_transferred
- https://github.com/OpenSC/OpenSC/releases/tag/0.24.0-rc1 x_transferred
- https://github.com/OpenSC/OpenSC/wiki/OpenSC-security-advisories x_transferred
- https://lists.debian.org/debian-lts-announce/2023/11/msg00024.html x_transferred
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj… x_transferred
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj… x_transferred
- http://www.openwall.com/lists/oss-security/2023/12/13/3
- RHSA-2023:7876 x_refsource_REDHAT vendor-advisory
- RHSA-2023:7879 x_refsource_REDHAT vendor-advisory
- https://access.redhat.com/security/cve/CVE-2023-40661 x_refsource_REDHAT vdb-entry
- RHBZ#2240913 issue-tracking x_refsource_REDHAT
- https://github.com/OpenSC/OpenSC/issues/2792#issuecomment-1674806651
- https://github.com/OpenSC/OpenSC/releases/tag/0.24.0-rc1
- https://github.com/OpenSC/OpenSC/wiki/OpenSC-security-advisories
- https://lists.debian.org/debian-lts-announce/2023/11/msg00024.html
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj…
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj…
- https://github.com/OpenSC/OpenSC/issues/2792#issuecomment-1674806651 x_transferred
- https://github.com/OpenSC/OpenSC/releases/tag/0.24.0-rc1 x_transferred
- https://github.com/OpenSC/OpenSC/wiki/OpenSC-security-advisories x_transferred
- https://lists.debian.org/debian-lts-announce/2023/11/msg00024.html x_transferred
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj… x_transferred
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj… x_transferred
- http://www.openwall.com/lists/oss-security/2023/12/13/3 x_transferred
- RHSA-2023:7876 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2023:7879 x_refsource_REDHAT vendor-advisory x_transferred
- https://access.redhat.com/security/cve/CVE-2023-40661 x_refsource_REDHAT vdb-entry x_transferred
- RHBZ#2240913 issue-tracking x_refsource_REDHAT x_transferred
- RHSA-2023:7876 x_refsource_REDHAT vendor-advisory
- RHSA-2023:7879 x_refsource_REDHAT vendor-advisory
- https://access.redhat.com/security/cve/CVE-2023-40661 x_refsource_REDHAT vdb-entry
- RHBZ#2240913 issue-tracking x_refsource_REDHAT
- https://github.com/OpenSC/OpenSC/issues/2792#issuecomment-1674806651
- https://github.com/OpenSC/OpenSC/releases/tag/0.24.0-rc1
- https://github.com/OpenSC/OpenSC/wiki/OpenSC-security-advisories
- http://www.openwall.com/lists/oss-security/2023/12/13/3 x_transferred
- RHSA-2023:7876 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2023:7879 x_refsource_REDHAT vendor-advisory x_transferred
- https://access.redhat.com/security/cve/CVE-2023-40661 x_refsource_REDHAT vdb-entry x_transferred
- RHBZ#2240913 issue-tracking x_refsource_REDHAT x_transferred
- https://github.com/OpenSC/OpenSC/issues/2792#issuecomment-1674806651 x_transferred
- https://github.com/OpenSC/OpenSC/releases/tag/0.24.0-rc1 x_transferred
- https://github.com/OpenSC/OpenSC/wiki/OpenSC-security-advisories x_transferred
- https://lists.debian.org/debian-lts-announce/2023/11/msg00024.html x_transferred
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj… x_transferred
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj… x_transferred
- RHSA-2023:7876 x_refsource_REDHAT vendor-advisory
- RHSA-2023:7879 x_refsource_REDHAT vendor-advisory
- https://access.redhat.com/security/cve/CVE-2023-40661 x_refsource_REDHAT vdb-entry
- RHBZ#2240913 issue-tracking x_refsource_REDHAT
- https://github.com/OpenSC/OpenSC/issues/2792#issuecomment-1674806651
- https://github.com/OpenSC/OpenSC/releases/tag/0.24.0-rc1
- https://github.com/OpenSC/OpenSC/wiki/OpenSC-security-advisories
- http://www.openwall.com/lists/oss-security/2023/12/13/3 x_transferred
- RHSA-2023:7876 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2023:7879 x_refsource_REDHAT vendor-advisory x_transferred
- https://access.redhat.com/security/cve/CVE-2023-40661 x_refsource_REDHAT vdb-entry x_transferred
- RHBZ#2240913 issue-tracking x_refsource_REDHAT x_transferred
- https://github.com/OpenSC/OpenSC/issues/2792#issuecomment-1674806651 x_transferred
- https://github.com/OpenSC/OpenSC/releases/tag/0.24.0-rc1 x_transferred
- https://github.com/OpenSC/OpenSC/wiki/OpenSC-security-advisories x_transferred
- https://lists.debian.org/debian-lts-announce/2023/11/msg00024.html x_transferred
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj… x_transferred
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj… x_transferred
- RHSA-2023:7876 x_refsource_REDHAT vendor-advisory
- RHSA-2023:7879 x_refsource_REDHAT vendor-advisory
- https://access.redhat.com/security/cve/CVE-2023-40661 x_refsource_REDHAT vdb-entry
- RHBZ#2240913 issue-tracking x_refsource_REDHAT
- https://github.com/OpenSC/OpenSC/issues/2792#issuecomment-1674806651
- https://github.com/OpenSC/OpenSC/releases/tag/0.24.0-rc1
- https://github.com/OpenSC/OpenSC/wiki/OpenSC-security-advisories
- https://lists.debian.org/debian-lts-announce/2023/11/msg00024.html x_transferred
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj… x_transferred
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj… x_transferred
- http://www.openwall.com/lists/oss-security/2023/12/13/3 x_transferred
- RHSA-2023:7876 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2023:7879 x_refsource_REDHAT vendor-advisory x_transferred
- https://access.redhat.com/security/cve/CVE-2023-40661 x_refsource_REDHAT vdb-entry x_transferred
- RHBZ#2240913 issue-tracking x_refsource_REDHAT x_transferred
- https://github.com/OpenSC/OpenSC/issues/2792#issuecomment-1674806651 x_transferred
- https://github.com/OpenSC/OpenSC/releases/tag/0.24.0-rc1 x_transferred
- https://github.com/OpenSC/OpenSC/wiki/OpenSC-security-advisories x_transferred
- RHSA-2023:7876 x_refsource_REDHAT vendor-advisory
- RHSA-2023:7879 x_refsource_REDHAT vendor-advisory
- https://access.redhat.com/security/cve/CVE-2023-40661 x_refsource_REDHAT vdb-entry
- RHBZ#2240913 issue-tracking x_refsource_REDHAT
- https://github.com/OpenSC/OpenSC/issues/2792#issuecomment-1674806651
- https://github.com/OpenSC/OpenSC/releases/tag/0.24.0-rc1
- https://github.com/OpenSC/OpenSC/wiki/OpenSC-security-advisories
- https://lists.debian.org/debian-lts-announce/2023/11/msg00024.html x_transferred
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj… x_transferred
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj… x_transferred
- http://www.openwall.com/lists/oss-security/2023/12/13/3 x_transferred
- RHSA-2023:7876 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2023:7879 x_refsource_REDHAT vendor-advisory x_transferred
- https://access.redhat.com/security/cve/CVE-2023-40661 x_refsource_REDHAT vdb-entry x_transferred
- RHBZ#2240913 issue-tracking x_refsource_REDHAT x_transferred
- https://github.com/OpenSC/OpenSC/issues/2792#issuecomment-1674806651 x_transferred
- https://github.com/OpenSC/OpenSC/releases/tag/0.24.0-rc1 x_transferred
- https://github.com/OpenSC/OpenSC/wiki/OpenSC-security-advisories x_transferred
- RHSA-2023:7876 x_refsource_REDHAT vendor-advisory
- RHSA-2023:7879 x_refsource_REDHAT vendor-advisory
- https://access.redhat.com/security/cve/CVE-2023-40661 x_refsource_REDHAT vdb-entry
- RHBZ#2240913 issue-tracking x_refsource_REDHAT
- https://github.com/OpenSC/OpenSC/issues/2792#issuecomment-1674806651
- https://github.com/OpenSC/OpenSC/releases/tag/0.24.0-rc1
- https://github.com/OpenSC/OpenSC/wiki/OpenSC-security-advisories
- http://www.openwall.com/lists/oss-security/2023/12/13/3 x_transferred
- RHSA-2023:7876 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2023:7879 x_refsource_REDHAT vendor-advisory x_transferred
- https://access.redhat.com/security/cve/CVE-2023-40661 x_refsource_REDHAT vdb-entry x_transferred
- RHBZ#2240913 issue-tracking x_refsource_REDHAT x_transferred
- https://github.com/OpenSC/OpenSC/issues/2792#issuecomment-1674806651 x_transferred
- https://github.com/OpenSC/OpenSC/releases/tag/0.24.0-rc1 x_transferred
- https://github.com/OpenSC/OpenSC/wiki/OpenSC-security-advisories x_transferred
- https://lists.debian.org/debian-lts-announce/2023/11/msg00024.html x_transferred
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj… x_transferred
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj… x_transferred
- https://lists.debian.org/debian-lts-announce/2024/12/msg00026.html
- https://access.redhat.com/security/cve/CVE-2023-40661 x_refsource_REDHAT vdb-entry
- RHBZ#2240913 issue-tracking x_refsource_REDHAT
- https://github.com/OpenSC/OpenSC/issues/2792#issuecomment-1674806651
- https://github.com/OpenSC/OpenSC/releases/tag/0.24.0-rc1
- https://github.com/OpenSC/OpenSC/wiki/OpenSC-security-advisories
- RHSA-2023:7876 x_refsource_REDHAT vendor-advisory
- RHSA-2023:7879 x_refsource_REDHAT vendor-advisory
- http://www.openwall.com/lists/oss-security/2023/12/13/3 x_transferred
- RHSA-2023:7876 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2023:7879 x_refsource_REDHAT vendor-advisory x_transferred
- https://access.redhat.com/security/cve/CVE-2023-40661 x_refsource_REDHAT vdb-entry x_transferred
- RHBZ#2240913 issue-tracking x_refsource_REDHAT x_transferred
- https://github.com/OpenSC/OpenSC/issues/2792#issuecomment-1674806651 x_transferred
- https://github.com/OpenSC/OpenSC/releases/tag/0.24.0-rc1 x_transferred
- https://github.com/OpenSC/OpenSC/wiki/OpenSC-security-advisories x_transferred
- https://lists.debian.org/debian-lts-announce/2023/11/msg00024.html x_transferred
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj… x_transferred
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj… x_transferred
- https://lists.debian.org/debian-lts-announce/2024/12/msg00026.html
Affected products
OpenSC
- ==0.24.0-rc1
- <0.24.0
opensc
- *
Matching in nixpkgs
pkgs.opensc
Set of libraries and utilities to access smart cards
-
nixos-unstable -
- nixpkgs-unstable 0.26.1
pkgs.openscad-lsp
LSP (Language Server Protocol) server for OpenSCAD
-
nixos-unstable -
- nixpkgs-unstable 2.0.1
pkgs.openscenegraph
3D graphics toolkit
-
nixos-unstable -
- nixpkgs-unstable 3.6.5
pkgs.openscad-unstable
3D parametric model compiler (unstable)
-
nixos-unstable -
- nixpkgs-unstable 2025-06-04
pkgs.kakounePlugins.openscad-kak
None
-
nixos-unstable -
- nixpkgs-unstable 2020-12-10
pkgs.vscode-extensions.antyos.openscad
OpenSCAD highlighting, snippets, and more for VSCode
-
nixos-unstable -
- nixpkgs-unstable 1.3.2
Package maintainers
-
@michaeladler Michael Adler <therisen06@gmail.com>
-
@bjornfor Bjørn Forsman <bjorn.forsman@gmail.com>
-
@7c6f434c Michael Raskin <7c6f434c@mail.ru>
-
@Curious-r Curious <curious@curious.host>
-
@c-h-johnson Charles Johnson <charles@charlesjohnson.name>
-
@pca006132 pca006132 <john.lck40@gmail.com>
-
@Tochiaha Tochukwu Ahanonu <tochiahan@proton.me>
-
@aanderse Aaron Andersen <aaron@fosslib.net>