vulnerability
Amazon Linux 2023: CVE-2024-45616: Low priority package update for opensc
Severity | CVSS | Published | Added | Modified |
---|---|---|---|---|
4 | (AV:L/AC:H/Au:N/C:P/I:P/A:P) | 09/02/2024 | 02/17/2025 | 02/17/2025 |
Severity
4
CVSS
(AV:L/AC:H/Au:N/C:P/I:P/A:P)
Published
09/02/2024
Added
02/17/2025
Modified
02/17/2025
Description
A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs.
The following problems were caused by insufficient control of the response APDU buffer and its length when communicating with the card.
The following problems were caused by insufficient control of the response APDU buffer and its length when communicating with the card.
Solution(s)
amazon-linux-2023-upgrade-openscamazon-linux-2023-upgrade-opensc-debuginfoamazon-linux-2023-upgrade-opensc-debugsource

NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.