Untriaged
Permalink
CVE-2024-45620
3.9 LOW
- CVSS version: 3.1
- Attack vector (AV): PHYSICAL
- Attack complexity (AC): HIGH
- Privileges required (PR): NONE
- User interaction (UI): NONE
- Scope (S): UNCHANGED
- Confidentiality impact (C): LOW
- Integrity impact (I): LOW
- Availability impact (A): LOW
Libopensc: incorrect handling of the length of buffers or files in pkcs15init
A vulnerability was found in the pkcs15-init tool in OpenSC. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. When buffers are partially filled with data, initialized parts of the buffer can be incorrectly accessed.
References
Affected products
opensc
libopensc
Matching in nixpkgs
pkgs.opensc
Set of libraries and utilities to access smart cards
pkgs.openscad
3D parametric model compiler
pkgs.openscap
NIST Certified SCAP 1.2 toolkit
pkgs.openscad-lsp
LSP (Language Server Protocol) server for OpenSCAD
pkgs.openscenegraph
3D graphics toolkit
pkgs.openscad-unstable
3D parametric model compiler (unstable)
-
nixos-unstable 2024-12-06
- nixpkgs-unstable 2024-12-06
- nixos-unstable-small 2024-12-06
pkgs.vimPlugins.vim-openscad
None
-
nixos-unstable 2022-07-26
- nixpkgs-unstable 2022-07-26
- nixos-unstable-small 2022-07-26
pkgs.vimPlugins.openscad-nvim
None
-
nixos-unstable 2024-04-13
- nixpkgs-unstable 2024-04-13
- nixos-unstable-small 2024-04-13
pkgs.kakounePlugins.openscad-kak
None
-
nixos-unstable 2020-12-10
- nixpkgs-unstable 2020-12-10
- nixos-unstable-small 2020-12-10
pkgs.vscode-extensions.antyos.openscad
OpenSCAD highlighting, snippets, and more for VSCode
Package maintainers
-
@michaeladler Michael Adler <therisen06@gmail.com>
-
@gebner Gabriel Ebner <gebner@gebner.org>
-
@bjornfor Bjørn Forsman <bjorn.forsman@gmail.com>
-
@7c6f434c Michael Raskin <7c6f434c@mail.ru>
-
@c-h-johnson Charles Johnson <charles@charlesjohnson.name>
-
@pca006132 pca006132 <john.lck40@gmail.com>
-
@Tochiaha Tochukwu Ahanonu <tochiahan@proton.me>
-
@aanderse Aaron Andersen <aaron@fosslib.net>