#VU98507 Heap-based buffer overflow in OpenSC - CVE-2024-8443
Published: October 14, 2024
OpenSC
OpenSC
Description
The vulnerability allows an attacker to bypass implemented security restrictions.
The vulnerability exists due to a boundary error in the libopensc OpenPGP driver. An attacker with physical access to the system can use a crafted USB device or smart card with malicious responses to the APDUs during the card enrollment process using the pkcs15-init tool to trigger an out-of-bound rights, possibly resulting in arbitrary code execution.