CVE-2009-1603
src/tools/pkcs11-tool.c in pkcs11-tool in OpenSC 0.11.7, when used with unspecified third-party PKCS#11 modules, generates RSA keys with incorrect public exponents, which allows attackers to read the cleartext form of messages that were intended to be…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.09%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
src/tools/pkcs11-tool.c in pkcs11-tool in OpenSC 0.11.7, when used with unspecified third-party PKCS#11 modules, generates RSA keys with incorrect public exponents, which allows attackers to read the cleartext form of messages that were intended to be encrypted.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 1.09% probability · 63th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-312
- Affected
- opensc-project/opensc · fedoraproject/fedora
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/35035Broken Link
- http://secunia.com/advisories/35293Broken Link
- http://secunia.com/advisories/35309Broken Link
- http://secunia.com/advisories/36074Broken Link
- http://security.gentoo.org/glsa/glsa-200908-01.xmlThird Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2009:123Broken Link
- http://www.opensc-project.org/pipermail/opensc-announce/2009-May/000025.htmlBroken Link
- http://www.openwall.com/lists/oss-security/2009/05/08/1Mailing List, Patch
- http://www.vupen.com/english/advisories/2009/1295Broken Link
- https://www.redhat.com/archives/fedora-package-announce/2009-June/msg00095.htmlMailing List
- https://www.redhat.com/archives/fedora-package-announce/2009-June/msg00097.htmlMailing List
- https://www.redhat.com/archives/fedora-package-announce/2009-May/msg01420.htmlMailing List
- https://www.redhat.com/archives/fedora-package-announce/2009-May/msg01432.htmlMailing List
- http://secunia.com/advisories/35035Broken Link
- http://secunia.com/advisories/35293Broken Link
- http://secunia.com/advisories/35309Broken Link
- http://secunia.com/advisories/36074Broken Link
- http://security.gentoo.org/glsa/glsa-200908-01.xmlThird Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2009:123Broken Link
- http://www.opensc-project.org/pipermail/opensc-announce/2009-May/000025.htmlBroken Link
- http://www.openwall.com/lists/oss-security/2009/05/08/1Mailing List, Patch
- http://www.vupen.com/english/advisories/2009/1295Broken Link
- https://www.redhat.com/archives/fedora-package-announce/2009-June/msg00095.htmlMailing List
- https://www.redhat.com/archives/fedora-package-announce/2009-June/msg00097.htmlMailing List
- https://www.redhat.com/archives/fedora-package-announce/2009-May/msg01420.htmlMailing List
- https://www.redhat.com/archives/fedora-package-announce/2009-May/msg01432.htmlMailing List
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.