CVE-2024-1454

Name
CVE-2024-1454
Description
The use-after-free vulnerability was found in the AuthentIC driver in OpenSC packages, occuring in the card enrolment process using pkcs15-init when a user or administrator enrols or modifies cards. An attacker must have physical access to the computer system and requires a crafted USB device or smart card to present the system with specially crafted responses to the APDUs, which are considered high complexity and low severity. This manipulation can allow for compromised card management operations during enrolment.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
vdb-entry https://access.redhat.com/security/cve/CVE-2024-1454
secalert@redhat.com https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=64898
issue-tracking https://bugzilla.redhat.com/show_bug.cgi?id=2263929
secalert@redhat.com https://github.com/OpenSC/OpenSC/commit/5835f0d4f6c033bd58806d33fa546908d39825c9
secalert@redhat.com https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RJI2FWLY24EOPALQ43YPQEZMEP3APPPI/
secalert@redhat.com https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OWIZ5ZLO5ECYPLSTESCF7I7PQO5X6ZSU/
secalert@redhat.com https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UECKC7X4IM4YZQ5KRQMNBNKNOXLZC7RZ/
af854a3a-2127-422b-91ae-364da2661108 https://lists.debian.org/debian-lts-announce/2024/12/msg00026.html

Match rules

CPE URI Source package Min version Max version
shopxo == 0.25.0 == 0.25.0

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
opensc edge-community 0.25.1-r0 Timo Teräs <timo.teras@iki.fi> fixed
opensc 3.22-community 0.25.1-r0 None fixed
opensc 3.21-community 0.25.1-r0 None fixed
opensc 3.20-community 0.25.1-r0 None fixed