Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2008-2235
Description:OpenSC before 0.11.5 uses weak permissions (ADMIN file control information of 00) for the 5015 directory on smart cards and USB crypto tokens running Siemens CardOS M4, which allows physically proximate attackers to change the PIN.
Test IDs: 1.3.6.1.4.1.25623.1.0.62958   1.3.6.1.4.1.25623.1.0.65919   1.3.6.1.4.1.25623.1.0.65621   1.3.6.1.4.1.25623.1.0.61379   1.3.6.1.4.1.25623.1.0.61528   1.3.6.1.4.1.25623.1.0.65526   1.3.6.1.4.1.25623.1.0.65925  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2008-2235
BugTraq ID: 30473
http://www.securityfocus.com/bid/30473
Debian Security Information: DSA-1627 (Google Search)
https://www.debian.org/security/2008/dsa-1627
https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00686.html
http://security.gentoo.org/glsa/glsa-200812-09.xml
http://www.mandriva.com/security/advisories?name=MDVSA-2008:183
http://www.opensc-project.org/pipermail/opensc-announce/2008-July/000020.html
http://secunia.com/advisories/31330
http://secunia.com/advisories/31360
http://secunia.com/advisories/32099
http://secunia.com/advisories/33115
http://secunia.com/advisories/34362
SuSE Security Announcement: SUSE-SR:2008:019 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2008-09/msg00005.html
SuSE Security Announcement: SUSE-SR:2009:004 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00002.html
XForce ISS Database: opensc-smartcard-cryptotoken-weak-security(44140)
https://exchange.xforce.ibmcloud.com/vulnerabilities/44140




© 1998-2025 E-Soft Inc. All rights reserved.