CVE-2008-3972: Medium severity suse opensc vulnerability
pkcs15-tool in OpenSC before 0.11.6 does not apply security updates to a smart card unless the card's label matches the "OpenSC" string, which might allow physically proximate attackers to exploit vulnerabilities that the card owner expected were patched, as demonstrated by exploitation of CVE-2008-2235.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-3972?
CVE-2008-3972 is classified as a medium severity vulnerability due to the specific conditions required for exploitation.
How do I fix CVE-2008-3972?
To fix CVE-2008-3972, upgrade OpenSC to version 0.11.6 or later where this issue is addressed.
What types of attacks can exploit CVE-2008-3972?
CVE-2008-3972 can be exploited by physically proximate attackers who can manipulate vulnerable smart cards.
Which versions of OpenSC are affected by CVE-2008-3972?
CVE-2008-3972 affects all OpenSC versions prior to 0.11.6, including versions from 0.4.0 to 0.11.5.
What are the implications of CVE-2008-3972 for users?
Users of vulnerable OpenSC versions may unwittingly allow attackers to exploit unpatched vulnerabilities on their smart cards.