CVE-2024-8443

A

heap-based buffer overflow vulnerability was found in the libopensc OpenPGP driver. A crafted USB device or smart card with malicious responses to the APDUs during the card enrollment process using the `pkcs15-init` tool may lead to out-of-bound rights, possibly resulting in arbitrary code execution.

Configurations

Configuration 1 (hide)

cpe:2.3:a:opensc_project:opensc:-:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*

History

03 Nov 2025, 23:17

Type Values Removed Values Added
References
  • () https://lists.debian.org/debian-lts-announce/2024/12/msg00026.html -

26 Sep 2024, 14:34

Type Values Removed Values Added
CWE CWE-787
CVSS v2 : unknown
v3 : 3.4
v2 : unknown
v3 : 2.9
References () https://access.redhat.com/security/cve/CVE-2024-8443 - () https://access.redhat.com/security/cve/CVE-2024-8443 - Vendor Advisory
References () https://bugzilla.redhat.com/show_bug.cgi?id=2310494 - () https://bugzilla.redhat.com/show_bug.cgi?id=2310494 - Issue Tracking, Vendor Advisory
Summary
  • (es) Se encontró una vulnerabilidad de desbordamiento de búfer en el montón en el controlador OpenPGP de libopensc. Un dispositivo USB o una tarjeta inteligente creados con respuestas maliciosas a las APDU durante el proceso de inscripción de la tarjeta mediante la herramienta `pkcs15-init` pueden generar derechos fuera de los límites, lo que posiblemente dé como resultado la ejecución de código arbitrario.
First Time Opensc Project opensc
Opensc Project
Redhat
Redhat enterprise Linux
CPE cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
cpe:2.3:a:opensc_project:opensc:-:*:*:*:*:*:*:*

10 Sep 2024, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-09-10 14:15

Updated : 2025-11-03 23:17


NVD link : CVE-2024-8443

Mitre link : CVE-2024-8443

CVE.ORG link : CVE-2024-8443


JSON object : View

CWE
CWE-122

Heap-based Buffer Overflow

CWE-787

Out-of-bounds Write