Untriaged
Permalink
CVE-2024-45618
3.9 LOW
- CVSS version: 3.1
- Attack vector (AV): PHYSICAL
- Attack complexity (AC): HIGH
- Privileges required (PR): NONE
- User interaction (UI): NONE
- Scope (S): UNCHANGED
- Confidentiality impact (C): LOW
- Integrity impact (I): LOW
- Availability impact (A): LOW
Libopensc: uninitialized values after incorrect or missing checking return values of functions in pkcs15init
A vulnerability was found in pkcs15-init in OpenSC. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. Insufficient or missing checking of return values of functions leads to unexpected work with variables that have not been initialized.
References
Affected products
opensc
libopensc
Matching in nixpkgs
pkgs.opensc
Set of libraries and utilities to access smart cards
pkgs.openscad
3D parametric model compiler
pkgs.openscad-lsp
LSP (Language Server Protocol) server for OpenSCAD
pkgs.openscenegraph
3D graphics toolkit
pkgs.openscad-unstable
3D parametric model compiler (unstable)
-
nixos-unstable 2024-12-06
- nixpkgs-unstable 2024-12-06
- nixos-unstable-small 2024-12-06
pkgs.vimPlugins.vim-openscad
None
-
nixos-unstable 2022-07-26
- nixpkgs-unstable 2022-07-26
- nixos-unstable-small 2022-07-26
pkgs.vimPlugins.openscad-nvim
None
-
nixos-unstable 2024-04-13
- nixpkgs-unstable 2024-04-13
- nixos-unstable-small 2024-04-13
pkgs.kakounePlugins.openscad-kak
None
-
nixos-unstable 2020-12-10
- nixpkgs-unstable 2020-12-10
- nixos-unstable-small 2020-12-10
pkgs.vscode-extensions.antyos.openscad
OpenSCAD highlighting, snippets, and more for VSCode
Package maintainers
-
@c-h-johnson Charles Johnson <charles@charlesjohnson.name>
-
@7c6f434c Michael Raskin <7c6f434c@mail.ru>
-
@pca006132 pca006132 <john.lck40@gmail.com>
-
@Tochiaha Tochukwu Ahanonu <tochiahan@proton.me>
-
@aanderse Aaron Andersen <aaron@fosslib.net>
-
@michaeladler Michael Adler <therisen06@gmail.com>
-
@gebner Gabriel Ebner <gebner@gebner.org>
-
@bjornfor Bjørn Forsman <bjorn.forsman@gmail.com>