Logo
vulnerabilityCVE-2024-8443
Name
CVE-2024-8443
Source
NVD ( link)Debian ( link)
Description
A heap-based buffer overflow vulnerability was found in the libopensc OpenPGP driver. A crafted USB device or smart card with malicious responses to the APDUs during the card enrollment process using the `pkcs15-init` tool may lead to out-of-bound rights, possibly resulting in arbitrary code execution.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
opensc
Not Affected

Vulnerability Ratings#


2.9
CVSSv31
2.9
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
0.27.1
Not Affected
buildroot
master
0.27.1
Not Affected
openwrt
master
0.27.1-r1
Not Affected
openwrt
openwrt-25.12
0.26.1-r1
Not Affected
yocto
kirkstone
0.22.0
Not Affected
yocto
scarthgap
0.25.1
Not Affected