OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, an attacker with physical access to the computer at the time user or administrator uses a token can cause a stack-buffer-overflow WRITE in card-oberthur. The attack requires crafted USB device or smart card that would present the system with specially crafted responses to the APDUs. This issue has been patched in version 0.27.0.
Metrics
Affected Vendors & Products
References
History
Fri, 03 Apr 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Opensc
Opensc opensc |
|
| Vendors & Products |
Opensc
Opensc opensc |
Wed, 01 Apr 2026 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Opensc Project
Opensc Project opensc |
|
| CPEs | cpe:2.3:a:opensc_project:opensc:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Opensc Project
Opensc Project opensc |
Tue, 31 Mar 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 31 Mar 2026 03:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-120 | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Mon, 30 Mar 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, an attacker with physical access to the computer at the time user or administrator uses a token can cause a stack-buffer-overflow WRITE in card-oberthur. The attack requires crafted USB device or smart card that would present the system with specially crafted responses to the APDUs. This issue has been patched in version 0.27.0. | |
| Title | OpenSC: Stack-buffer-overflow WRITE in card-oberthur | |
| Weaknesses | CWE-121 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2026-03-30T17:06:16.996Z
Updated: 2026-03-31T18:53:46.404Z
Reserved: 2025-11-24T23:01:29.678Z
Link: CVE-2025-66215
Updated: 2026-03-31T18:50:37.583Z
Status : Analyzed
Published: 2026-03-30T18:16:18.350
Modified: 2026-04-01T17:28:49.457
Link: CVE-2025-66215