VDB
CVE-2009-0368
CVE-2009-0368
PUBLISHED
Reported by mitre · Published March 2, 2009
OpenSC before 0.11.7 allows physically proximate attackers to bypass intended PIN requirements and read private data objects via a (1) low level APDU command or (2) debugging tool, as demonstrated by reading the 4601 or 4701 file with the opensc-explorer or opensc-tool program.
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| n/a | n/a | n/a, n/a |
Timeline
- Mar 2, 2009 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 25, 2023 EPSS Score
References
- 34120 third-party-advisoryx_refsource_SECUNIA
- 33922 vdb-entryx_refsource_BID
- opensc-pkcs-unauth-access(48958) vdb-entryx_refsource_XF
- 34362 third-party-advisoryx_refsource_SECUNIA
- 35065 third-party-advisoryx_refsource_SECUNIA
- FEDORA-2009-2266 vendor-advisoryx_refsource_FEDORA
- [oss-security] 20090226 OpenSC Security Advisory mailing-listx_refsource_MLIST
- DSA-1734 vendor-advisoryx_refsource_DEBIAN
- 34377 third-party-advisoryx_refsource_SECUNIA
- 36074 third-party-advisoryx_refsource_SECUNIA
- FEDORA-2009-2267 vendor-advisoryx_refsource_FEDORA
- SUSE-SR:2009:010 vendor-advisoryx_refsource_SUSE
- 34052 third-party-advisoryx_refsource_SECUNIA
- [opensc-announce] 20090226 OpenSC Security Advisory mailing-listx_refsource_MLIST
- GLSA-200908-01 vendor-advisoryx_refsource_GENTOO