Описание
A vulnerability was found in OpenSC where PKCS#1 encryption padding removal is not implemented as side-channel resistant. This issue may result in the potential leak of private data.
Пакеты
Пакет | Статус | Версия исправления | Релиз | Тип |
---|---|---|---|---|
opensc | fixed | 0.25.0~rc1-1 | package | |
opensc | fixed | 0.23.0-0.3+deb12u2 | bookworm | package |
opensc | no-dsa | buster | package |
Примечания
https://bugzilla.redhat.com/show_bug.cgi?id=2248685
https://github.com/OpenSC/OpenSC/wiki/CVE-2023-5992
https://github.com/OpenSC/OpenSC/security/advisories/GHSA-h6ww-xfc2-jw4h
https://github.com/OpenSC/OpenSC/pull/2948
Regression fix: https://github.com/OpenSC/OpenSC/pull/3077 (0.25.1)
EPSS
Связанные уязвимости
A vulnerability was found in OpenSC where PKCS#1 encryption padding removal is not implemented as side-channel resistant. This issue may result in the potential leak of private data.
A vulnerability was found in OpenSC where PKCS#1 encryption padding removal is not implemented as side-channel resistant. This issue may result in the potential leak of private data.
A vulnerability was found in OpenSC where PKCS#1 encryption padding removal is not implemented as side-channel resistant. This issue may result in the potential leak of private data.
EPSS