Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-48721.json
JSON Data
https://api.test.osv.dev/v1/vulns/AZL-48721
Upstream
Published
2024-09-03T22:15:04Z
Modified
2026-04-01T05:16:04.979291Z
Severity
  • 3.9 (Low) CVSS_V3 - CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L CVSS Calculator
Summary
CVE-2024-45616 affecting package opensc for versions less than 0.26.1-1
Details

A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs.

The following problems were caused by insufficient control of the response APDU buffer and its length when communicating with the card.

References

Affected packages

Azure Linux:3 / opensc

Package

Name
opensc
Purl
pkg:rpm/azure-linux/opensc

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.26.1-1

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-48721.json"