CVE-2009-0368: Low severity opensc-project OpenSC vulnerability
OpenSC before 0.11.7 allows physically proximate attackers to bypass intended PIN requirements and read private data objects via a (1) low level APDU command or (2) debugging tool, as demonstrated by reading the 4601 or 4701 file with the opensc-explorer or opensc-tool program.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-0368?
CVE-2009-0368 is classified as a medium severity vulnerability due to the risk of unauthorized access to private data.
How do I fix CVE-2009-0368?
To fix CVE-2009-0368, upgrade OpenSC to version 0.11.7 or later.
What types of attacks can exploit CVE-2009-0368?
CVE-2009-0368 can be exploited using low level APDU commands or debugging tools by physically proximate attackers.
Which versions of OpenSC are affected by CVE-2009-0368?
OpenSC versions prior to 0.11.7, including 0.11.6 and earlier, are affected by CVE-2009-0368.
What is the impact of CVE-2009-0368?
The impact of CVE-2009-0368 includes the potential for attackers to bypass PIN requirements and access private data.