Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2010-4523


Multiple stack-based buffer overflows in libopensc in OpenSC 0.11.13 and earlier allow physically proximate attackers to execute arbitrary code via a long serial-number field on a smart card, related to (1) card-acos5.c, (2) card-atrust-acos.c, and (3) card-starcos.c.


Published

2011-01-07T20:00:04.733

Last Modified

2025-04-11T00:51:21.963

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 7.2 (HIGH)

CVSSv2 Vector

AV:L/AC:L/Au:N/C:C/I:C/A:C

  • Access Vector: LOCAL
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

3.9

Impact Score

10.0

Weaknesses
  • Type: Primary
    CWE-119

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application opensc-project opensc ≤ 0.11.13 Yes
Application opensc-project opensc 0.3.2 Yes
Application opensc-project opensc 0.3.5 Yes
Application opensc-project opensc 0.4.0 Yes
Application opensc-project opensc 0.5.0 Yes
Application opensc-project opensc 0.6.0 Yes
Application opensc-project opensc 0.6.1 Yes
Application opensc-project opensc 0.7.0 Yes
Application opensc-project opensc 0.8 Yes
Application opensc-project opensc 0.8.0 Yes
Application opensc-project opensc 0.8.0.0 Yes
Application opensc-project opensc 0.8.1 Yes
Application opensc-project opensc 0.9 Yes
Application opensc-project opensc 0.9.2 Yes
Application opensc-project opensc 0.9.3 Yes
Application opensc-project opensc 0.9.4 Yes
Application opensc-project opensc 0.9.5 Yes
Application opensc-project opensc 0.9.6 Yes
Application opensc-project opensc 0.9.7 Yes
Application opensc-project opensc 0.9.7 Yes
Application opensc-project opensc 0.9.7 Yes
Application opensc-project opensc 0.9.8 Yes
Application opensc-project opensc 0.10.0 Yes
Application opensc-project opensc 0.10.1 Yes
Application opensc-project opensc 0.11.0 Yes
Application opensc-project opensc 0.11.1 Yes
Application opensc-project opensc 0.11.2 Yes
Application opensc-project opensc 0.11.3 Yes
Application opensc-project opensc 0.11.3 Yes
Application opensc-project opensc 0.11.4 Yes
Application opensc-project opensc 0.11.5 Yes
Application opensc-project opensc 0.11.6 Yes
Application opensc-project opensc 0.11.7 Yes
Application opensc-project opensc 0.11.8 Yes
Application opensc-project opensc 0.11.9 Yes
Application opensc-project opensc 0.11.10 Yes
Application opensc-project opensc 0.11.11 Yes
Application opensc-project opensc 0.11.12 Yes

References