3.4 LOW
- CVSS version: 3.1
- Attack vector (AV): PHYSICAL
- Attack complexity (AC): HIGH
- Privileges required (PR): NONE
- User interaction (UI): REQUIRED
- Scope (S): CHANGED
- Confidentiality impact (C): LOW
- Integrity impact (I): LOW
- Availability impact (A): NONE
Opensc: memory use after free in authentic driver when updating token info
The use-after-free vulnerability was found in the AuthentIC driver in OpenSC packages, occuring in the card enrolment process using pkcs15-init when a user or administrator enrols or modifies cards. An attacker must have physical access to the computer system and requires a crafted USB device or smart card to present the system with specially crafted responses to the APDUs, which are considered high complexity and low severity. This manipulation can allow for compromised card management operations during enrolment.
References
Affected products
- ==0.25.0
Matching in nixpkgs
pkgs.opensc
Set of libraries and utilities to access smart cards
pkgs.openscad
3D parametric model compiler
pkgs.openscap
NIST Certified SCAP 1.2 toolkit
pkgs.openscad-lsp
LSP (Language Server Protocol) server for OpenSCAD
pkgs.openscenegraph
3D graphics toolkit
pkgs.openscad-unstable
3D parametric model compiler (unstable)
-
nixos-unstable 2024-12-06
- nixpkgs-unstable 2024-12-06
- nixos-unstable-small 2024-12-06
pkgs.vimPlugins.vim-openscad
None
-
nixos-unstable 2022-07-26
- nixpkgs-unstable 2022-07-26
- nixos-unstable-small 2022-07-26
pkgs.vimPlugins.openscad-nvim
None
-
nixos-unstable 2024-04-13
- nixpkgs-unstable 2024-04-13
- nixos-unstable-small 2024-04-13
pkgs.kakounePlugins.openscad-kak
None
-
nixos-unstable 2020-12-10
- nixpkgs-unstable 2020-12-10
- nixos-unstable-small 2020-12-10
pkgs.vscode-extensions.antyos.openscad
OpenSCAD highlighting, snippets, and more for VSCode
Package maintainers
-
@michaeladler Michael Adler <therisen06@gmail.com>
-
@gebner Gabriel Ebner <gebner@gebner.org>
-
@bjornfor Bjørn Forsman <bjorn.forsman@gmail.com>
-
@7c6f434c Michael Raskin <7c6f434c@mail.ru>
-
@c-h-johnson Charles Johnson <charles@charlesjohnson.name>
-
@pca006132 pca006132 <john.lck40@gmail.com>
-
@Tochiaha Tochukwu Ahanonu <tochiahan@proton.me>
-
@aanderse Aaron Andersen <aaron@fosslib.net>