Untriaged
Permalink
CVE-2024-45616
3.9 LOW
- CVSS version: 3.1
- Attack vector (AV): PHYSICAL
- Attack complexity (AC): HIGH
- Privileges required (PR): NONE
- User interaction (UI): NONE
- Scope (S): UNCHANGED
- Confidentiality impact (C): LOW
- Integrity impact (I): LOW
- Availability impact (A): LOW
Libopensc: uninitialized values after incorrect check or usage of apdu response values in libopensc
A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. When buffers are partially filled with data, initialized parts of the buffer can be incorrectly accessed.
References
- https://access.redhat.com/security/cve/CVE-2024-45616 x_refsource_REDHAT vdb-entry
- RHBZ#2309290 issue-tracking x_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2024-45616 x_refsource_REDHAT vdb-entry
- RHBZ#2309290 issue-tracking x_refsource_REDHAT
- RHBZ#2309290 issue-tracking x_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2024-45616 x_refsource_REDHAT vdb-entry
- https://access.redhat.com/security/cve/CVE-2024-45616 x_refsource_REDHAT vdb-entry
- RHBZ#2309290 issue-tracking x_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2024-45616 x_refsource_REDHAT vdb-entry
- RHBZ#2309290 issue-tracking x_refsource_REDHAT
- RHBZ#2309290 issue-tracking x_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2024-45616 x_refsource_REDHAT vdb-entry
- https://access.redhat.com/security/cve/CVE-2024-45616 x_refsource_REDHAT vdb-entry
- RHBZ#2309290 issue-tracking x_refsource_REDHAT
- https://lists.debian.org/debian-lts-announce/2024/12/msg00026.html
- https://access.redhat.com/security/cve/CVE-2024-45616 x_refsource_REDHAT vdb-entry
- RHBZ#2309290 issue-tracking x_refsource_REDHAT
- https://lists.debian.org/debian-lts-announce/2024/12/msg00026.html
Affected products
opensc
libopensc
- <0.26.0
Matching in nixpkgs
pkgs.opensc
Set of libraries and utilities to access smart cards
-
nixos-unstable -
- nixpkgs-unstable 0.26.1
pkgs.openscad-lsp
LSP (Language Server Protocol) server for OpenSCAD
-
nixos-unstable -
- nixpkgs-unstable 2.0.1
pkgs.openscenegraph
3D graphics toolkit
-
nixos-unstable -
- nixpkgs-unstable 3.6.5
pkgs.openscad-unstable
3D parametric model compiler (unstable)
-
nixos-unstable -
- nixpkgs-unstable 2025-06-04
pkgs.kakounePlugins.openscad-kak
None
-
nixos-unstable -
- nixpkgs-unstable 2020-12-10
pkgs.vscode-extensions.antyos.openscad
OpenSCAD highlighting, snippets, and more for VSCode
-
nixos-unstable -
- nixpkgs-unstable 1.3.2
Package maintainers
-
@michaeladler Michael Adler <therisen06@gmail.com>
-
@bjornfor Bjørn Forsman <bjorn.forsman@gmail.com>
-
@7c6f434c Michael Raskin <7c6f434c@mail.ru>
-
@Curious-r Curious <curious@curious.host>
-
@c-h-johnson Charles Johnson <charles@charlesjohnson.name>
-
@pca006132 pca006132 <john.lck40@gmail.com>
-
@Tochiaha Tochukwu Ahanonu <tochiahan@proton.me>
-
@aanderse Aaron Andersen <aaron@fosslib.net>