CVE-2023-2977
CVSS 3.1 Score 7.1 of 10 (high)
Details
Published Jun 1, 2023
Updated: Jan 9, 2025
CWE ID 125
CWE ID 119
Summary
CVE-2023-2977 is a buffer overrun vulnerability discovered in OpenSC. A malformed ASN1 context in a smart card package can cause the cardos_have_verifyrc_package function to incorrectly calculate the remaining length, resulting in a possible heap-based buffer out-of-bounds read. If Address Sanitizer (ASAN) is enabled during compilation, a crash occurs. Further potential impacts of this vulnerability include information leak or additional damage.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Red Hat Enterprise Linux
Affected Vendors
- Red Hat