#VU77320 Out-of-bounds read in OpenSC - CVE-2023-2977
Published: June 14, 2023
OpenSC
OpenSC
Description
The vulnerability allows a local user to gain access to potentially sensitive information.
The vulnerability exists due to a boundary condition within the cardos_have_verifyrc_package() function in pkcs15 cardos_have_verifyrc_package. A local user can pass a smart card package with malformed ASN1 context to the application, trigger an out-of-bounds read error and read contents of memory on the system.