CVE-2009-0368

Publication date 2 March 2009

Last updated 24 July 2024


Ubuntu priority

OpenSC before 0.11.7 allows physically proximate attackers to bypass intended PIN requirements and read private data objects via a (1) low level APDU command or (2) debugging tool, as demonstrated by reading the 4601 or 4701 file with the opensc-explorer or opensc-tool program.

Status

Package Ubuntu Release Status
opensc 11.10 oneiric
Not affected
11.04 natty
Not affected
10.10 maverick
Not affected
10.04 LTS lucid
Not affected
9.10 karmic
Not affected
9.04 jaunty
Fixed 0.11.4-5ubuntu1.1
8.10 intrepid Ignored end of life, was needs-triage
8.04 LTS hardy Ignored end of life
7.10 gutsy Ignored end of life, was needs-triage
6.06 LTS dapper Ignored end of life