Unrated severityNVD Advisory· Published Mar 2, 2009· Updated Apr 23, 2026
CVE-2009-0368
CVE-2009-0368
Description
OpenSC before 0.11.7 allows physically proximate attackers to bypass intended PIN requirements and read private data objects via a (1) low level APDU command or (2) debugging tool, as demonstrated by reading the 4601 or 4701 file with the opensc-explorer or opensc-tool program.
Affected products
31cpe:2.3:a:opensc-project:opensc:*:*:*:*:*:*:*:*+ 30 more
- cpe:2.3:a:opensc-project:opensc:*:*:*:*:*:*:*:*range: <=0.11.6
- cpe:2.3:a:opensc-project:opensc:0.10.0:*:*:*:*:*:*:*
- cpe:2.3:a:opensc-project:opensc:0.10.1:*:*:*:*:*:*:*
- cpe:2.3:a:opensc-project:opensc:0.11.0:*:*:*:*:*:*:*
- cpe:2.3:a:opensc-project:opensc:0.11.1:*:*:*:*:*:*:*
- cpe:2.3:a:opensc-project:opensc:0.11.2:*:*:*:*:*:*:*
- cpe:2.3:a:opensc-project:opensc:0.11.3:*:*:*:*:*:*:*
- cpe:2.3:a:opensc-project:opensc:0.11.3:pre3:*:*:*:*:*:*
- cpe:2.3:a:opensc-project:opensc:0.11.4:*:*:*:*:*:*:*
- cpe:2.3:a:opensc-project:opensc:0.11.5:*:*:*:*:*:*:*
- cpe:2.3:a:opensc-project:opensc:0.3.2:*:*:*:*:*:*:*
- cpe:2.3:a:opensc-project:opensc:0.3.5:*:*:*:*:*:*:*
- cpe:2.3:a:opensc-project:opensc:0.4.0:*:*:*:*:*:*:*
- cpe:2.3:a:opensc-project:opensc:0.5.0:*:*:*:*:*:*:*
- cpe:2.3:a:opensc-project:opensc:0.6.0:*:*:*:*:*:*:*
- cpe:2.3:a:opensc-project:opensc:0.6.1:*:*:*:*:*:*:*
- cpe:2.3:a:opensc-project:opensc:0.7.0:*:*:*:*:*:*:*
- cpe:2.3:a:opensc-project:opensc:0.8:*:*:*:*:*:*:*
- cpe:2.3:a:opensc-project:opensc:0.8.0:*:*:*:*:*:*:*
- cpe:2.3:a:opensc-project:opensc:0.8.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:opensc-project:opensc:0.8.1:*:*:*:*:*:*:*
- cpe:2.3:a:opensc-project:opensc:0.9:*:*:*:*:*:*:*
- cpe:2.3:a:opensc-project:opensc:0.9.2:*:*:*:*:*:*:*
- cpe:2.3:a:opensc-project:opensc:0.9.3:*:*:*:*:*:*:*
- cpe:2.3:a:opensc-project:opensc:0.9.4:*:*:*:*:*:*:*
- cpe:2.3:a:opensc-project:opensc:0.9.5:*:*:*:*:*:*:*
- cpe:2.3:a:opensc-project:opensc:0.9.6:*:*:*:*:*:*:*
- cpe:2.3:a:opensc-project:opensc:0.9.7:*:*:*:*:*:*:*
- cpe:2.3:a:opensc-project:opensc:0.9.7:b:*:*:*:*:*:*
- cpe:2.3:a:opensc-project:opensc:0.9.7:d:*:*:*:*:*:*
- cpe:2.3:a:opensc-project:opensc:0.9.8:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
15- openwall.com/lists/oss-security/2009/02/26/1nvdPatch
- www.securityfocus.com/bid/33922nvdExploitPatch
- secunia.com/advisories/34052nvdVendor Advisory
- www.opensc-project.org/pipermail/opensc-announce/2009-February/000023.htmlnvdVendor Advisory
- lists.opensuse.org/opensuse-security-announce/2009-05/msg00000.htmlnvd
- secunia.com/advisories/34120nvd
- secunia.com/advisories/34362nvd
- secunia.com/advisories/34377nvd
- secunia.com/advisories/35065nvd
- secunia.com/advisories/36074nvd
- security.gentoo.org/glsa/glsa-200908-01.xmlnvd
- www.debian.org/security/2009/dsa-1734nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/48958nvd
- www.redhat.com/archives/fedora-package-announce/2009-March/msg00673.htmlnvd
- www.redhat.com/archives/fedora-package-announce/2009-March/msg00686.htmlnvd
News mentions
0No linked articles in our index yet.