pkcs15-tool in OpenSC before 0.11.6 does not apply security updates to a smart card unless the card's label matches the "OpenSC" string, which might allow physically proximate attackers to exploit vulnerabilities that the card owner expected were patched, as demonstrated by exploitation of CVE-2008-2235.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2008-09-10T15:00:00
Updated: 2024-08-07T10:00:42.172Z
Reserved: 2008-09-09T00:00:00
Link: CVE-2008-3972
Vulnrichment
No data.
NVD
Status : Modified
Published: 2008-09-11T01:13:47.807
Modified: 2024-11-21T00:50:36.663
Link: CVE-2008-3972
Redhat
No data.