VDB
CVE-2010-4523
CVE-2010-4523
PUBLISHED
CVSS 7.199999809265137 HIGH
Multiple stack-based buffer overflows in libopensc in OpenSC 0.11.13 and earlier allow physically proximate attackers to execute arbitrary code via a long serial-number field on a smart card, related to (1) card-acos5.c, (2) card-atrust-acos.c, and (3) card-starcos.c.
EPSS 0.26% · 49.8th percentile
Risk Scores
CVSS 2.0
7.199999809265137
EPSS Score
0.26%
49.8th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| opensc-project | opensc | 0, 0.3.2, 0.3.5 |
| n/a | n/a | n/a |
Timeline
- Jan 7, 2011 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 2, 2023 EPSS Score
- May 25, 2023 EPSS Score
References
- http://www.h-online.com/open/news/item/When-a-smart-card-can-root-your-computer-1154829.html url
- 43068 third-party-advisory
- ADV-2011-0212 vdb
- [oss-security] 20101222 Re: CVE request: opensc buffer overflow mailing-list
- https://www.opensc-project.org/opensc/changeset/4913 url
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=607427 url
- MDVSA-2011:011 vendor-advisory
- FEDORA-2010-19193 vendor-advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=664831 url
- 42807 third-party-advisory
- http://labs.mwrinfosecurity.com/files/Advisories/mwri_opensc-get-serial-buffer-overflow_2010-12-13.pdf url
- SUSE-SR:2011:002 vendor-advisory
- ADV-2011-0109 vdb
- 42658 third-party-advisory
- ADV-2011-0009 vdb
- https://bugs.launchpad.net/ubuntu/+source/opensc/+bug/692483 url
- FEDORA-2010-19192 vendor-advisory
- [oss-security] 20101221 CVE request: opensc buffer overflow mailing-list
- 45435 vdb
- https://nvd.nist.gov/vuln/detail/CVE-2010-4523 advisory