DEBIAN-CVE-2008-2235

Source
https://security-tracker.debian.org/tracker/CVE-2008-2235
Import Source
https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2008-2235.json
JSON Data
https://api.test.osv.dev/v1/vulns/DEBIAN-CVE-2008-2235
Upstream
Published
2008-08-01T14:41:00Z
Modified
2025-09-19T06:09:32Z
Summary
[none]
Details

OpenSC before 0.11.5 uses weak permissions (ADMIN file control information of 00) for the 5015 directory on smart cards and USB crypto tokens running Siemens CardOS M4, which allows physically proximate attackers to change the PIN.

References

Affected packages

Debian:11 / opensc

Package

Name
opensc
Purl
pkg:deb/debian/opensc?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.11.4-4

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:12 / opensc

Package

Name
opensc
Purl
pkg:deb/debian/opensc?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.11.4-4

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13 / opensc

Package

Name
opensc
Purl
pkg:deb/debian/opensc?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.11.4-4

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:14 / opensc

Package

Name
opensc
Purl
pkg:deb/debian/opensc?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.11.4-4

Ecosystem specific

{
    "urgency": "not yet assigned"
}