First published: Wed Sep 10 2008(Updated: )
pkcs15-tool in OpenSC before 0.11.6 does not apply security updates to a smart card unless the card's label matches the "OpenSC" string, which might allow physically proximate attackers to exploit vulnerabilities that the card owner expected were patched, as demonstrated by exploitation of CVE-2008-2235.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Opensc-project Opensc | <=0.11.5 | |
Opensc-project Opensc | =0.4.0 | |
Opensc-project Opensc | =0.5.0 | |
Opensc-project Opensc | =0.6.0 | |
Opensc-project Opensc | =0.6.1 | |
Opensc-project Opensc | =0.7.0 | |
Opensc-project Opensc | =0.8.0 | |
Opensc-project Opensc | =0.8.1 | |
Opensc-project Opensc | =0.9.2 | |
Opensc-project Opensc | =0.9.3 | |
Opensc-project Opensc | =0.9.4 | |
Opensc-project Opensc | =0.9.5 | |
Opensc-project Opensc | =0.9.6 | |
Opensc-project Opensc | =0.10.0 | |
Opensc-project Opensc | =0.10.1 | |
Opensc-project Opensc | =0.11.0 | |
Opensc-project Opensc | =0.11.1 | |
Opensc-project Opensc | =0.11.2 | |
Opensc-project Opensc | =0.11.3 | |
Opensc-project Opensc | =0.11.3-pre3 | |
Opensc-project Opensc | =0.11.4 | |
Siemens CardOS | =m4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.