Untriaged
Permalink
CVE-2024-1454
3.4 LOW
- CVSS version: 3.1
- Attack vector (AV): PHYSICAL
- Attack complexity (AC): HIGH
- Privileges required (PR): NONE
- User interaction (UI): REQUIRED
- Scope (S): CHANGED
- Confidentiality impact (C): LOW
- Integrity impact (I): LOW
- Availability impact (A): NONE
Opensc: memory use after free in authentic driver when updating token info
The use-after-free vulnerability was found in the AuthentIC driver in OpenSC packages, occuring in the card enrolment process using pkcs15-init when a user or administrator enrols or modifies cards. An attacker must have physical access to the computer system and requires a crafted USB device or smart card to present the system with specially crafted responses to the APDUs, which are considered high complexity and low severity. This manipulation can allow for compromised card management operations during enrolment.
References
- https://access.redhat.com/security/cve/CVE-2024-1454 x_refsource_REDHAT vdb-entry
- https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=64898
- RHBZ#2263929 issue-tracking x_refsource_REDHAT
- https://github.com/OpenSC/OpenSC/commit/5835f0d4f6c033bd58806d33fa546908d39825c9
- https://access.redhat.com/security/cve/CVE-2024-1454 x_refsource_REDHAT vdb-entry
- https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=64898
- RHBZ#2263929 issue-tracking x_refsource_REDHAT
- https://github.com/OpenSC/OpenSC/commit/5835f0d4f6c033bd58806d33fa546908d39825c9
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj…
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj…
- https://access.redhat.com/security/cve/CVE-2024-1454 x_refsource_REDHAT vdb-entry
- https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=64898
- RHBZ#2263929 issue-tracking x_refsource_REDHAT
- https://github.com/OpenSC/OpenSC/commit/5835f0d4f6c033bd58806d33fa546908d39825c9
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj…
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj…
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj…
- https://access.redhat.com/security/cve/CVE-2024-1454 x_refsource_REDHAT vdb-entry
- https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=64898
- RHBZ#2263929 issue-tracking x_refsource_REDHAT
- https://github.com/OpenSC/OpenSC/commit/5835f0d4f6c033bd58806d33fa546908d39825c9
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj…
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj…
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj…
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj… x_transferred
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj… x_transferred
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj… x_transferred
- https://access.redhat.com/security/cve/CVE-2024-1454 x_refsource_REDHAT vdb-entry x_transferred
- https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=64898 x_transferred
- RHBZ#2263929 issue-tracking x_refsource_REDHAT x_transferred
- https://github.com/OpenSC/OpenSC/commit/5835f0d4f6c033bd58806d33fa546908d39825c9 x_transferred
- https://access.redhat.com/security/cve/CVE-2024-1454 x_refsource_REDHAT vdb-entry
- https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=64898
- RHBZ#2263929 issue-tracking x_refsource_REDHAT
- https://github.com/OpenSC/OpenSC/commit/5835f0d4f6c033bd58806d33fa546908d39825c9
- https://access.redhat.com/security/cve/CVE-2024-1454 x_refsource_REDHAT vdb-entry x_transferred
- https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=64898 x_transferred
- RHBZ#2263929 issue-tracking x_refsource_REDHAT x_transferred
- https://github.com/OpenSC/OpenSC/commit/5835f0d4f6c033bd58806d33fa546908d39825c9 x_transferred
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj… x_transferred
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj… x_transferred
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj… x_transferred
- https://access.redhat.com/security/cve/CVE-2024-1454 x_refsource_REDHAT vdb-entry
- https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=64898
- RHBZ#2263929 issue-tracking x_refsource_REDHAT
- https://github.com/OpenSC/OpenSC/commit/5835f0d4f6c033bd58806d33fa546908d39825c9
- https://access.redhat.com/security/cve/CVE-2024-1454 x_refsource_REDHAT vdb-entry x_transferred
- https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=64898 x_transferred
- RHBZ#2263929 issue-tracking x_refsource_REDHAT x_transferred
- https://github.com/OpenSC/OpenSC/commit/5835f0d4f6c033bd58806d33fa546908d39825c9 x_transferred
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj… x_transferred
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj… x_transferred
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj… x_transferred
- https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=64898
- RHBZ#2263929 issue-tracking x_refsource_REDHAT
- https://github.com/OpenSC/OpenSC/commit/5835f0d4f6c033bd58806d33fa546908d39825c9
- https://access.redhat.com/security/cve/CVE-2024-1454 x_refsource_REDHAT vdb-entry
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj… x_transferred
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj… x_transferred
- https://access.redhat.com/security/cve/CVE-2024-1454 x_refsource_REDHAT vdb-entry x_transferred
- https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=64898 x_transferred
- RHBZ#2263929 issue-tracking x_refsource_REDHAT x_transferred
- https://github.com/OpenSC/OpenSC/commit/5835f0d4f6c033bd58806d33fa546908d39825c9 x_transferred
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj… x_transferred
- RHBZ#2263929 issue-tracking x_refsource_REDHAT
- https://github.com/OpenSC/OpenSC/commit/5835f0d4f6c033bd58806d33fa546908d39825c9
- https://access.redhat.com/security/cve/CVE-2024-1454 x_refsource_REDHAT vdb-entry
- https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=64898
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj… x_transferred
- https://access.redhat.com/security/cve/CVE-2024-1454 x_refsource_REDHAT vdb-entry x_transferred
- https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=64898 x_transferred
- RHBZ#2263929 issue-tracking x_refsource_REDHAT x_transferred
- https://github.com/OpenSC/OpenSC/commit/5835f0d4f6c033bd58806d33fa546908d39825c9 x_transferred
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj… x_transferred
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj… x_transferred
- https://access.redhat.com/security/cve/CVE-2024-1454 x_refsource_REDHAT vdb-entry
- https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=64898
- RHBZ#2263929 issue-tracking x_refsource_REDHAT
- https://github.com/OpenSC/OpenSC/commit/5835f0d4f6c033bd58806d33fa546908d39825c9
- https://access.redhat.com/security/cve/CVE-2024-1454 x_refsource_REDHAT vdb-entry x_transferred
- https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=64898 x_transferred
- RHBZ#2263929 issue-tracking x_refsource_REDHAT x_transferred
- https://github.com/OpenSC/OpenSC/commit/5835f0d4f6c033bd58806d33fa546908d39825c9 x_transferred
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj… x_transferred
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj… x_transferred
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj… x_transferred
- https://lists.debian.org/debian-lts-announce/2024/12/msg00026.html
- https://github.com/OpenSC/OpenSC/commit/5835f0d4f6c033bd58806d33fa546908d39825c9
- https://access.redhat.com/security/cve/CVE-2024-1454 x_refsource_REDHAT vdb-entry
- https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=64898
- RHBZ#2263929 issue-tracking x_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2024-1454 x_refsource_REDHAT vdb-entry x_transferred
- https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=64898 x_transferred
- RHBZ#2263929 issue-tracking x_refsource_REDHAT x_transferred
- https://github.com/OpenSC/OpenSC/commit/5835f0d4f6c033bd58806d33fa546908d39825c9 x_transferred
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj… x_transferred
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj… x_transferred
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj… x_transferred
- https://lists.debian.org/debian-lts-announce/2024/12/msg00026.html
Affected products
opensc
- ==0.25.0
Matching in nixpkgs
pkgs.opensc
Set of libraries and utilities to access smart cards
-
nixos-unstable -
- nixpkgs-unstable 0.26.1
pkgs.openscad-lsp
LSP (Language Server Protocol) server for OpenSCAD
-
nixos-unstable -
- nixpkgs-unstable 2.0.1
pkgs.openscenegraph
3D graphics toolkit
-
nixos-unstable -
- nixpkgs-unstable 3.6.5
pkgs.openscad-unstable
3D parametric model compiler (unstable)
-
nixos-unstable -
- nixpkgs-unstable 2025-06-04
pkgs.kakounePlugins.openscad-kak
None
-
nixos-unstable -
- nixpkgs-unstable 2020-12-10
pkgs.vscode-extensions.antyos.openscad
OpenSCAD highlighting, snippets, and more for VSCode
-
nixos-unstable -
- nixpkgs-unstable 1.3.2
Package maintainers
-
@michaeladler Michael Adler <therisen06@gmail.com>
-
@bjornfor Bjørn Forsman <bjorn.forsman@gmail.com>
-
@7c6f434c Michael Raskin <7c6f434c@mail.ru>
-
@Curious-r Curious <curious@curious.host>
-
@c-h-johnson Charles Johnson <charles@charlesjohnson.name>
-
@pca006132 pca006132 <john.lck40@gmail.com>
-
@Tochiaha Tochukwu Ahanonu <tochiahan@proton.me>
-
@aanderse Aaron Andersen <aaron@fosslib.net>