opensc-0.20.0-2.el8

エラータID: AXSA:2021-1113:01

Release date: 
Thursday, January 7, 2021 - 06:22
Subject: 
opensc-0.20.0-2.el8
Affected Channels: 
Asianux Server 8 for x86_64
Severity: 
Moderate
Description: 

The OpenSC set of libraries and utilities provides support for working with smart cards. OpenSC focuses on cards that support cryptographic operations and enables their use for authentication, mail encryption, or digital signatures.

The following packages have been upgraded to a later upstream version: opensc (0.20.0).

Security Fix(es):

* opensc: Out-of-bounds access of an ASN.1 Bitstring in decode_bit_string in libopensc/asn1.c (CVE-2019-15945)

* opensc: Out-of-bounds access of an ASN.1 Octet string in asn1_decode_entry in libopensc/asn1.c (CVE-2019-15946)

* opensc: Improper handling of buffer limits for CAC certificates (CVE-2019-19481)

* opensc: Double free in coolkey_free_private_data in libopensc/card-coolkey.c (CVE-2019-20792)

* opensc: Incorrect read operation during parsing of a SETCOS file attribute (CVE-2019-19479)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

CVE-2019-15945
OpenSC before 0.20.0-rc1 has an out-of-bounds access of an ASN.1 Bitstring in decode_bit_string in libopensc/asn1.c.
CVE-2019-15946
OpenSC before 0.20.0-rc1 has an out-of-bounds access of an ASN.1 Octet string in asn1_decode_entry in libopensc/asn1.c.
CVE-2019-19479
An issue was discovered in OpenSC through 0.19.0 and 0.20.x through 0.20.0-rc3. libopensc/card-setcos.c has an incorrect read operation during parsing of a SETCOS file attribute.
CVE-2019-19481
An issue was discovered in OpenSC through 0.19.0 and 0.20.x through 0.20.0-rc3. libopensc/card-cac1.c mishandles buffer limits for CAC certificates.
CVE-2019-20792
OpenSC before 0.20.0 has a double free in coolkey_free_private_data because coolkey_add_object in libopensc/card-coolkey.c lacks a uniqueness check.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. opensc-0.20.0-2.el8.src.rpm
    MD5: 26786a95a04171486997bc387255e053
    SHA-256: 0c0f55a17967fe141fda2e246a8c2165b5a11d4bd6e655b1e95603a19eb745f8
    Size: 2.10 MB

Asianux Server 8 for x86_64
  1. opensc-0.20.0-2.el8.x86_64.rpm
    MD5: 513c8c41a81f73e12b65909d5d068df0
    SHA-256: 3f2648862db6057e259a20654b315c8c0b200b109fca777946c81066e9181893
    Size: 1.27 MB
  2. opensc-0.20.0-2.el8.i686.rpm
    MD5: 42db4fbbafa94633cd0f71faa95c7d77
    SHA-256: 2450a913d335996d0610c10f440f6161f51652c84486ba52fa1b21323b14e046
    Size: 1.28 MB