Your submission was sent successfully! Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

CVE-2009-1603

Published: 11 May 2009

src/tools/pkcs11-tool.c in pkcs11-tool in OpenSC 0.11.7, when used with unspecified third-party PKCS#11 modules, generates RSA keys with incorrect public exponents, which allows attackers to read the cleartext form of messages that were intended to be encrypted.

Notes

AuthorNote
jdstrand
per Debian, 0.11.4-5+lenny1 and earlier not affected

Priority

Low

Cvss 3 Severity Score

7.5

Score breakdown

Status

Package Release Status
opensc
Launchpad, Ubuntu, Debian
dapper Not vulnerable

hardy Not vulnerable

intrepid Not vulnerable

jaunty Not vulnerable

karmic Ignored
(end of life)
lucid Not vulnerable
(0.11.8-1ubuntu1)
maverick Not vulnerable
(0.11.8-1ubuntu1)
natty Not vulnerable
(0.11.8-1ubuntu1)
upstream
Released (0.11.8)

Severity score breakdown

Parameter Value
Base score 7.5
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Scope Unchanged
Confidentiality High
Integrity impact None
Availability impact None
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N