Unrated severityNVD Advisory· Published Jan 7, 2011· Updated Apr 29, 2026
CVE-2010-4523
CVE-2010-4523
Description
Multiple stack-based buffer overflows in libopensc in OpenSC 0.11.13 and earlier allow physically proximate attackers to execute arbitrary code via a long serial-number field on a smart card, related to (1) card-acos5.c, (2) card-atrust-acos.c, and (3) card-starcos.c.
Affected products
38cpe:2.3:a:opensc-project:opensc:*:*:*:*:*:*:*:*+ 37 more
- cpe:2.3:a:opensc-project:opensc:*:*:*:*:*:*:*:*range: <=0.11.13
- cpe:2.3:a:opensc-project:opensc:0.10.0:*:*:*:*:*:*:*
- cpe:2.3:a:opensc-project:opensc:0.10.1:*:*:*:*:*:*:*
- cpe:2.3:a:opensc-project:opensc:0.11.0:*:*:*:*:*:*:*
- cpe:2.3:a:opensc-project:opensc:0.11.1:*:*:*:*:*:*:*
- cpe:2.3:a:opensc-project:opensc:0.11.10:*:*:*:*:*:*:*
- cpe:2.3:a:opensc-project:opensc:0.11.11:*:*:*:*:*:*:*
- cpe:2.3:a:opensc-project:opensc:0.11.12:*:*:*:*:*:*:*
- cpe:2.3:a:opensc-project:opensc:0.11.2:*:*:*:*:*:*:*
- cpe:2.3:a:opensc-project:opensc:0.11.3:*:*:*:*:*:*:*
- cpe:2.3:a:opensc-project:opensc:0.11.3:pre3:*:*:*:*:*:*
- cpe:2.3:a:opensc-project:opensc:0.11.4:*:*:*:*:*:*:*
- cpe:2.3:a:opensc-project:opensc:0.11.5:*:*:*:*:*:*:*
- cpe:2.3:a:opensc-project:opensc:0.11.6:*:*:*:*:*:*:*
- cpe:2.3:a:opensc-project:opensc:0.11.7:*:*:*:*:*:*:*
- cpe:2.3:a:opensc-project:opensc:0.11.8:*:*:*:*:*:*:*
- cpe:2.3:a:opensc-project:opensc:0.11.9:*:*:*:*:*:*:*
- cpe:2.3:a:opensc-project:opensc:0.3.2:*:*:*:*:*:*:*
- cpe:2.3:a:opensc-project:opensc:0.3.5:*:*:*:*:*:*:*
- cpe:2.3:a:opensc-project:opensc:0.4.0:*:*:*:*:*:*:*
- cpe:2.3:a:opensc-project:opensc:0.5.0:*:*:*:*:*:*:*
- cpe:2.3:a:opensc-project:opensc:0.6.0:*:*:*:*:*:*:*
- cpe:2.3:a:opensc-project:opensc:0.6.1:*:*:*:*:*:*:*
- cpe:2.3:a:opensc-project:opensc:0.7.0:*:*:*:*:*:*:*
- cpe:2.3:a:opensc-project:opensc:0.8:*:*:*:*:*:*:*
- cpe:2.3:a:opensc-project:opensc:0.8.0:*:*:*:*:*:*:*
- cpe:2.3:a:opensc-project:opensc:0.8.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:opensc-project:opensc:0.8.1:*:*:*:*:*:*:*
- cpe:2.3:a:opensc-project:opensc:0.9:*:*:*:*:*:*:*
- cpe:2.3:a:opensc-project:opensc:0.9.2:*:*:*:*:*:*:*
- cpe:2.3:a:opensc-project:opensc:0.9.3:*:*:*:*:*:*:*
- cpe:2.3:a:opensc-project:opensc:0.9.4:*:*:*:*:*:*:*
- cpe:2.3:a:opensc-project:opensc:0.9.5:*:*:*:*:*:*:*
- cpe:2.3:a:opensc-project:opensc:0.9.6:*:*:*:*:*:*:*
- cpe:2.3:a:opensc-project:opensc:0.9.7:*:*:*:*:*:*:*
- cpe:2.3:a:opensc-project:opensc:0.9.7:b:*:*:*:*:*:*
- cpe:2.3:a:opensc-project:opensc:0.9.7:d:*:*:*:*:*:*
- cpe:2.3:a:opensc-project:opensc:0.9.8:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
19- www.h-online.com/open/news/item/When-a-smart-card-can-root-your-computer-1154829.htmlnvdPatch
- bugs.launchpad.net/ubuntu/+source/opensc/+bug/692483nvdPatch
- www.opensc-project.org/opensc/changeset/4913nvdPatch
- bugs.debian.org/cgi-bin/bugreport.cginvdExploitPatch
- labs.mwrinfosecurity.com/files/Advisories/mwri_opensc-get-serial-buffer-overflow_2010-12-13.pdfnvdExploitPatch
- openwall.com/lists/oss-security/2010/12/21/2nvdExploitPatch
- openwall.com/lists/oss-security/2010/12/22/3nvdExploitPatch
- bugzilla.redhat.com/show_bug.cginvdExploitPatch
- secunia.com/advisories/42658nvdVendor Advisory
- secunia.com/advisories/42807nvdVendor Advisory
- www.vupen.com/english/advisories/2011/0009nvdVendor Advisory
- lists.fedoraproject.org/pipermail/package-announce/2011-January/052777.htmlnvd
- lists.fedoraproject.org/pipermail/package-announce/2011-January/052796.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.htmlnvd
- secunia.com/advisories/43068nvd
- www.mandriva.com/security/advisoriesnvd
- www.securityfocus.com/bid/45435nvd
- www.vupen.com/english/advisories/2011/0109nvd
- www.vupen.com/english/advisories/2011/0212nvd
News mentions
0No linked articles in our index yet.