UBUNTU-CVE-2023-2977
Dashboard / Vulnerabilities / UBUNTU-CVE-2023-2977
UBUNTU-CVE-2023-2977
Summary:
Details: A vulnerbility was found in OpenSC. This security flaw cause a buffer overrun vulnerability in pkcs15 cardos_have_verifyrc_package. The attacker can supply a smart card package with malformed ASN1 context. The cardos_have_verifyrc_package function scans the ASN1 buffer for 2 tags, where remaining length is wrongly caculated due to moved starting pointer. This leads to possible heap-based buffer oob read. In cases where ASAN is enabled while compiling this causes a crash. Further info leak or more damage is possible.
References: https://ubuntu.com/security/CVE-2023-2977, https://github.com/OpenSC/OpenSC/issues/2785, https://github.com/OpenSC/OpenSC/pull/2787, https://www.cve.org/CVERecord?id=CVE-2023-2977, https://ubuntu.com/security/notices/USN-7346-1, https://ubuntu.com/security/notices/USN-7346-3
Affected packages
Package
Name: opensc
Purl: pkg:deb/ubuntu/[email protected]+esm2?arch=source&distro=esm-apps/xenial
Affected ranges
Type: ECOSYSTEM
Events:
