CVE-2023-2977

CVSS 3.1 Score 7.1 of 10 (high)

Details

Published Jun 1, 2023
Updated: Jan 9, 2025
CWE ID 125
CWE ID 119

Summary

CVE-2023-2977 is a buffer overrun vulnerability discovered in OpenSC. A malformed ASN1 context in a smart card package can cause the cardos_have_verifyrc_package function to incorrectly calculate the remaining length, resulting in a possible heap-based buffer out-of-bounds read. If Address Sanitizer (ASAN) is enabled during compilation, a crash occurs. Further potential impacts of this vulnerability include information leak or additional damage.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Red Hat Enterprise Linux

Affected Vendors

  • Red Hat