everal memory vulnerabilities were identified within the OpenSC packages, particularly in the card enrollment process using pkcs15-init when a user or administrator enrolls cards. To take advantage of these flaws, an attacker must have physical access to the computer system and employ a custom-crafted USB device or smart card to manipulate responses to APDUs. This manipulation can potentially allow compromise key generation, certificate loading, and other card management operations during enrollment.
03 Nov 2025, 22:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
21 Nov 2024, 08:19
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.4 |
| References |
|
|
| References | () https://access.redhat.com/errata/RHSA-2023:7876 - | |
| References | () https://access.redhat.com/errata/RHSA-2023:7879 - | |
| References | () https://access.redhat.com/security/cve/CVE-2023-40661 - Third Party Advisory | |
| References | () https://bugzilla.redhat.com/show_bug.cgi?id=2240913 - Issue Tracking | |
| References | () https://github.com/OpenSC/OpenSC/issues/2792#issuecomment-1674806651 - VDB Entry | |
| References | () https://github.com/OpenSC/OpenSC/releases/tag/0.24.0-rc1 - Release Notes | |
| References | () https://github.com/OpenSC/OpenSC/wiki/OpenSC-security-advisories - Vendor Advisory |
16 Sep 2024, 17:15
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Published : 2023-11-06 17:15
Updated : 2025-11-03 22:16
NVD link : CVE-2023-40661
Mitre link : CVE-2023-40661
CVE.ORG link : CVE-2023-40661
JSON object : View
Improper Restriction of Operations within the Bounds of a Memory Buffer