CVE-2009-1603: High severity opensc-project OpenSC vulnerability
src/tools/pkcs11-tool.c in pkcs11-tool in OpenSC 0.11.7, when used with unspecified third-party PKCS#11 modules, generates RSA keys with incorrect public exponents, which allows attackers to read the cleartext form of messages that were intended to be encrypted.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-1603?
CVE-2009-1603 has been assigned a medium severity level due to its potential impact on the confidentiality of encrypted messages.
How do I fix CVE-2009-1603?
To fix CVE-2009-1603, update to a later version of OpenSC that addresses this vulnerability.
Which versions of OpenSC are affected by CVE-2009-1603?
CVE-2009-1603 specifically affects OpenSC version 0.11.7.
What kind of attacks can exploit CVE-2009-1603?
CVE-2009-1603 can be exploited by attackers to read cleartext messages that were intended to be encrypted.
What software should I be aware of in relation to CVE-2009-1603?
In addition to OpenSC 0.11.7, CVE-2009-1603 may also impact certain versions of Fedora that utilize affected PKCS#11 modules.