← Back

CVE-2023-4535

nvd nist
Published: Nov 6, 2023Modified: Jun 17, 2026

JSON object

Loading...
3.8
Vector
CVSS:3.1/AV:P/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L
Exploitability: 0.4 / Impact: 3.4
Source: NVD

Description

An out-of-bounds read vulnerability was found in OpenSC packages within the MyEID driver when handling symmetric key encryption. Exploiting this flaw requires an attacker to have physical access to the computer and a specially crafted USB device or smart card. This flaw allows the attacker to manipulate APDU responses and potentially gain unauthorized access to sensitive data, compromising the system's security.

Affected (6)

Opensc
1 product
Fedora
1 product
Enterprise Linux
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Opensc Project
Version 0.23.0
Version 0.23.0 rc1
Version 0.23.0 rc2
Configuration B
3 vulnerable
Vulnerable SoftwareAffected Versions
Fedoraproject
Version 38
Version 39
Version 9.0

References (16)

Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Issue Tracking
Source: secalert@redhat.com
Issue TrackingPatch
Source: secalert@redhat.com
Release Notes
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue Tracking
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingPatch
Source: af854a3a-2127-422b-91ae-364da2661108
Release Notes
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.