cvedb.io
CVE-2023-2977
HIGH · CVSS 7.1
EPSS exploitation probability: 0%
Published 2023-06-01T01:15:17.917 · Last modified 2026-06-17T05:53:55.687

Summary

A vulnerbility was found in OpenSC. This security flaw cause a buffer overrun vulnerability in pkcs15 cardos_have_verifyrc_package. The attacker can supply a smart card package with malformed ASN1 context. The cardos_have_verifyrc_package function scans the ASN1 buffer for 2 tags, where remaining length is wrongly caculated due to moved starting pointer. This leads to possible heap-based buffer oob read. In cases where ASAN is enabled while compiling this causes a crash. Further info leak or more damage is possible.

Affected products

opensc_project — opensc

Does this affect you?

Add your gear to cvedb and we'll alert you only when opensc_project ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.