REDHAT-BUG-2309289: Low severity OpenSC pkcs15-init vulnerability
The reported issues are part of the card enrollment process using the pkcs15-init tool. The attack requires a crafted USB device or smart card that would present the system with specially crafted responses to the APDUs, so they are considered high complexity and low severity.
When buffers are partially filled with data, uninitialized parts of the buffer can be incorrectly accessed. The uninitialized variables were reflected in the following functions:
- starcoswritepukey - iaseccsdoparse - setcosgeneratekey - schsmdeterminefreeid
Originally reported by Matteo Marini (Sapienza University of Rome)
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2309289?
The severity of REDHAT-BUG-2309289 is classified as low.
How do I fix REDHAT-BUG-2309289?
There is no direct fix provided for REDHAT-BUG-2309289, but users should avoid using untrusted USB devices or smart cards during the card enrollment process.
What type of attack does REDHAT-BUG-2309289 involve?
REDHAT-BUG-2309289 involves an attack using a crafted USB device or smart card that can respond with specially crafted APDU responses.
What system processes are affected by REDHAT-BUG-2309289?
The card enrollment process using the pkcs15-init tool is affected by REDHAT-BUG-2309289.
What is required to exploit REDHAT-BUG-2309289?
Exploiting REDHAT-BUG-2309289 requires high complexity and a crafted USB device or smart card.