OpenSC Smart Card Serial Number Multiple Buffer Overflow Vulnerabilities (Win)
Summary:
Check for the version of OpenSC
Description:
Overview: This host is installed with OpenSC and is prone to multiple buffer overflow vulnerabilities.
Vulnerability Insight: The flaws are due to boundary errors in the 'acos_get_serialnr()', 'acos5_get_serialnr()', and 'starcos_get_serialnr()' functions when reading out the serial number of smart cards.
Impact: Successful exploitation could allow remote attackers to execute arbitrary code in the context of the application. Failed attacks will cause denial of service conditions.
Impact Level: Application
Affected Software/OS: OpenSC version 0.11.13 and prior.