VDB
CVE-2009-1603
CVE-2009-1603
PUBLISHED
CVSS 7.5 HIGH
src/tools/pkcs11-tool.c in pkcs11-tool in OpenSC 0.11.7, when used with unspecified third-party PKCS#11 modules, generates RSA keys with incorrect public exponents, which allows attackers to read the cleartext form of messages that were intended to be encrypted.
EPSS 1.05% · 77.9th percentile
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Score
1.05%
77.9th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| opensc-project | opensc | 0.11.7 |
| n/a | n/a | * |
| fedoraproject | fedora | 9, 10, 11 |
Timeline
- May 11, 2009 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 25, 2023 EPSS Score
References
- http://secunia.com/advisories/35309 url
- ADV-2009-1295 vdb
- 35293 third-party-advisory
- FEDORA-2009-4919 vendor-advisory
- [oss-security] 20090508 OpenSC 0.11.8 released with security update mailing-list
- FEDORA-2009-4967 vendor-advisory
- FEDORA-2009-4928 vendor-advisory
- 36074 third-party-advisory
- MDVSA-2009:123 vendor-advisory
- FEDORA-2009-4883 vendor-advisory
- 35035 third-party-advisory
- [opensc-announce] 20090508 OpenSC 0.11.8 released with security update mailing-list
- GLSA-200908-01 vendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2009-1603 advisory