Heap-based buffer overflow in OpenSC - CVE-2024-8443

 

Heap-based buffer overflow in OpenSC - CVE-2024-8443

Published: October 14, 2024


Vulnerability identifier: #VU98507
CSH Severity: Low
CVSS v4: 5.4 [CVSS:4.0/AV:P/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-8443
CWE-ID: CWE-122
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows an attacker to bypass implemented security restrictions.

The vulnerability exists due to a boundary error in the libopensc OpenPGP driver. An attacker with physical access to the system can use a crafted USB device or smart card with malicious responses to the APDUs during the card enrollment process using the pkcs15-init tool to trigger an out-of-bound rights, possibly resulting in arbitrary code execution.


Affected software

OpenSC
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
openSUSE Leap Micro
Basesystem Module
openSUSE Leap
Ubuntu
openEuler
opensc-pkcs11 (Ubuntu package)
opensc (Ubuntu package)
opensc
opensc-debugsource
opensc-debuginfo
opensc-help
opensc-32bit
opensc-64bit-debuginfo
opensc-64bit
opensc-32bit-debuginfo

How to mitigate CVE-2024-8443

Install updates from vendor's website.

OpenSC - update to 0.26.0 rc1
opensc-pkcs11 (Ubuntu package) - addressed in versions Ubuntu Pro, 0.25.1-2ubuntu1.1
opensc (Ubuntu package) - addressed in versions Ubuntu Pro, 0.25.1-2ubuntu1.1
opensc - addressed in versions 0.13.0-3.31.1, 0.19.0-150100.3.31.1, 0.22.0-150400.3.12.1, 0.22.0-150600.11.3.1
opensc-debugsource - addressed in versions 0.13.0-3.31.1, 0.19.0-150100.3.31.1, 0.22.0-150400.3.12.1, 0.22.0-150600.11.3.1
opensc-debuginfo - addressed in versions 0.13.0-3.31.1, 0.19.0-150100.3.31.1, 0.22.0-150400.3.12.1, 0.22.0-150600.11.3.1
opensc-help - update to 0.21.0-11
opensc-debugsource - update to 0.21.0-11
opensc-debuginfo - update to 0.21.0-11
opensc - update to 0.21.0-11
opensc-32bit - addressed in versions 0.22.0-150400.3.12.1, 0.22.0-150600.11.3.1
opensc-64bit-debuginfo - addressed in versions 0.22.0-150400.3.12.1, 0.22.0-150600.11.3.1
opensc-64bit - addressed in versions 0.22.0-150400.3.12.1, 0.22.0-150600.11.3.1
opensc-32bit-debuginfo - addressed in versions 0.22.0-150400.3.12.1, 0.22.0-150600.11.3.1

External References

Related Security Bulletins