OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, an attacker with physical access to the computer at the time user or administrator uses a token can cause a stack-buffer-overflow write in GET RESPONSE. The attack requires crafted USB device or smart card that would present the system with specially crafted responses to the APDUs. This issue has been patched in version 0.27.0.
Metrics
Affected Vendors & Products
References
History
Mon, 30 Mar 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, an attacker with physical access to the computer at the time user or administrator uses a token can cause a stack-buffer-overflow write in GET RESPONSE. The attack requires crafted USB device or smart card that would present the system with specially crafted responses to the APDUs. This issue has been patched in version 0.27.0. | |
| Title | OpenSC: Stack-buffer-overflow WRITE in GET RESPONSE | |
| Weaknesses | CWE-121 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-03-30T18:38:21.684Z
Reserved: 2025-05-29T16:34:07.176Z
Link: CVE-2025-49010
No data.
Status : Received
Published: 2026-03-30T18:16:16.950
Modified: 2026-03-30T18:16:16.950
Link: CVE-2025-49010
No data.
OpenCVE Enrichment
No data.