CVE-2023-4535
Summary
| CVE | CVE-2023-4535 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-11-06 17:15:00 UTC |
| Updated | 2023-11-14 17:11:00 UTC |
| Description | An out-of-bounds read vulnerability was found in OpenSC packages within the MyEID driver when handling symmetric key encryption. Exploiting this flaw requires an attacker to have physical access to the computer and a specially crafted USB device or smart card. This flaw allows the attacker to manipulate APDU responses and potentially gain unauthorized access to sensitive data, compromising the system's security. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| myeid: fixed CID 380538 Out-of-bounds read (OVERRUN) · OpenSC/OpenSC@f1993dc · GitHub |
MISC |
github.com |
|
| 2240914 – (CVE-2023-4535) CVE-2023-4535 OpenSC: out-of-bounds read in MyEID driver handling encryption using symmetric keys |
MISC |
bugzilla.redhat.com |
|
| OpenSC security advisories · OpenSC/OpenSC Wiki · GitHub |
MISC |
github.com |
|
| Release 0.24.0-rc1 · OpenSC/OpenSC · GitHub |
MISC |
github.com |
|
| New release 0.24.0 · Issue #2792 · OpenSC/OpenSC · GitHub |
MISC |
github.com |
|
| cve-details |
MISC |
access.redhat.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 161246 Oracle Enterprise Linux Security Update for opensc (ELSA-2023-7879)
- 242627 Red Hat Update for opensc (RHSA-2023:7879)
- 284825 Fedora Security Update for opensc (FEDORA-2023-c7e4c9af51)
- 285094 Fedora Security Update for opensc (FEDORA-2023-a854153d7a)
- 356637 Amazon Linux Security Advisory for opensc : ALAS2023-2023-417
- 506145 Alpine Linux Security Update for opensc
- 907691 Common Base Linux Mariner (CBL-Mariner) Security Update for opensc (31945-1)
- 941511 AlmaLinux Security Update for opensc (ALSA-2023:7879)