VDB
BDU%3A2025-04907
BDU%3A2025-04907
PUBLISHED
CVSS 6.199999809265137 MEDIUM
Уязвимость функции cardos_have_verifyrc_package набора программных инструментов и библиотек для работы со смарт-картами OpenSC, позволяющая нарушителю вызвать отказ в обслуживании
Risk Scores
CVSS 2.0
6.199999809265137
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Canonical Ltd., Сообщество свободного программного обеспечения, Red Hat Inc., ООО «РусБИТех-Астра», АО «ИВК», Fedora Project, OpenSC Project, ООО «Открытая мобильная платформа» | Ubuntu, Debian GNU/Linux, Red Hat Enterprise Linux, Astra Linux Special Edition (запись в едином реестре российских программ №369), Альт 8 СП (запись в едином реестре российских программ №4305), Fedora, АЛЬТ СП 10, Opensc, ОС Аврора (запись в едином реестре российских программ №1543) | |
| n/a | OpenSC | opensc-0.23.0 |
Timeline
- Jun 1, 2023 CVE Published
- Jan 9, 2025 PoC Published
- Oct 29, 2025 CVE Updated
References
- https://access.redhat.com/security/cve/cve-2023-2977 url
- https://security-tracker.debian.org/tracker/CVE-2023-2977 url
- https://ubuntu.com/security/CVE-2023-2977 url
- https://github.com/OpenSC/OpenSC/pull/2787 url
- https://wiki.astralinux.ru/astra-linux-se47-bulletin-2025-1020SE47 url
- https://github.com/OpenSC/OpenSC/releases/tag/0.23.0 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2211088 url
- [debian-lts-announce] 20230621 [SECURITY] [DLA 3463-1] opensc security update mailing-list
- FEDORA-2023-29530cc60b vendor-advisory
- FEDORA-2023-2afb831742 vendor-advisory
- https://access.redhat.com/security/cve/CVE-2023-2977 url
- https://lists.debian.org/debian-lts-announce/2024/12/msg00026.html url
- https://github.com/OpenSC/OpenSC/issues/2785 url
- https://www.suse.com/security/cve/CVE-2023-2977.html advisory
- https://altsp.su/obnovleniya-bezopasnosti/ advisory
- https://cve.omp.ru/bb27514 advisory
- https://wiki.astralinux.ru/astra-linux-se17-bulletin-2025-0923SE17 advisory