Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2022:1041-1

Опубликовано: 30 мар. 2022
Источник: suse-cvrf

Описание

Security update for opensc

This update for opensc fixes the following issues:

Security issues fixed:

  • CVE-2021-42780: Fixed use after return in insert_pin() (bsc#1192005).
  • CVE-2021-42779: Fixed use after free in sc_file_valid() (bsc#1191992).
  • CVE-2021-42781: Fixed multiple heap buffer overflows in pkcs15-oberthur.c (bsc#1192000).
  • CVE-2021-42782: Stack buffer overflow issues in various places (bsc#1191957).
  • CVE-2019-6502: Fixed a memory leak in sc_context_create() (bsc#1122756).
  • CVE-2020-26570: Fixed a heap based buffer overflow in sc_oberthur_read_file (bsc#1177364).
  • CVE-2020-26572: Prevent out of bounds write (bsc#1177378)
  • CVE-2020-26571: gemsafe GPK smart card software driver stack-based buffer overflow (bsc#1177380)
  • CVE-2019-15946: out-of-bounds access of an ASN.1 Octet string in asn1_decode_entry (bsc#1149747)
  • CVE-2019-19479: incorrect read operation during parsing of a SETCOS file attribute (bsc#1158256)
  • CVE-2019-15945: Fixed an out-of-bounds access of an ASN.1 Bitstring in decode_bit_string (bsc#1149746).
  • CVE-2019-19481: Fixed an improper handling of buffer limits for CAC certificates (bsc#1158305).
  • CVE-2019-20792: Fixed a double free in coolkey_free_private_data (bsc#1170809).

Non-security issues fixed:

  • Fixes segmentation fault in 'pkcs11-tool.c'. (bsc#1114649)

Список пакетов

SUSE Linux Enterprise High Performance Computing 15-ESPOS
opensc-0.18.0-150000.3.23.1
SUSE Linux Enterprise High Performance Computing 15-LTSS
opensc-0.18.0-150000.3.23.1
SUSE Linux Enterprise Server 15-LTSS
opensc-0.18.0-150000.3.23.1
SUSE Linux Enterprise Server for SAP Applications 15
opensc-0.18.0-150000.3.23.1

Описание

OpenSC before 0.20.0-rc1 has an out-of-bounds access of an ASN.1 Bitstring in decode_bit_string in libopensc/asn1.c.


Затронутые продукты
SUSE Linux Enterprise High Performance Computing 15-ESPOS:opensc-0.18.0-150000.3.23.1
SUSE Linux Enterprise High Performance Computing 15-LTSS:opensc-0.18.0-150000.3.23.1
SUSE Linux Enterprise Server 15-LTSS:opensc-0.18.0-150000.3.23.1
SUSE Linux Enterprise Server for SAP Applications 15:opensc-0.18.0-150000.3.23.1

Ссылки

Описание

OpenSC before 0.20.0-rc1 has an out-of-bounds access of an ASN.1 Octet string in asn1_decode_entry in libopensc/asn1.c.


Затронутые продукты
SUSE Linux Enterprise High Performance Computing 15-ESPOS:opensc-0.18.0-150000.3.23.1
SUSE Linux Enterprise High Performance Computing 15-LTSS:opensc-0.18.0-150000.3.23.1
SUSE Linux Enterprise Server 15-LTSS:opensc-0.18.0-150000.3.23.1
SUSE Linux Enterprise Server for SAP Applications 15:opensc-0.18.0-150000.3.23.1

Ссылки

Описание

An issue was discovered in OpenSC through 0.19.0 and 0.20.x through 0.20.0-rc3. libopensc/card-setcos.c has an incorrect read operation during parsing of a SETCOS file attribute.


Затронутые продукты
SUSE Linux Enterprise High Performance Computing 15-ESPOS:opensc-0.18.0-150000.3.23.1
SUSE Linux Enterprise High Performance Computing 15-LTSS:opensc-0.18.0-150000.3.23.1
SUSE Linux Enterprise Server 15-LTSS:opensc-0.18.0-150000.3.23.1
SUSE Linux Enterprise Server for SAP Applications 15:opensc-0.18.0-150000.3.23.1

Ссылки

Описание

An issue was discovered in OpenSC through 0.19.0 and 0.20.x through 0.20.0-rc3. libopensc/card-cac1.c mishandles buffer limits for CAC certificates.


Затронутые продукты
SUSE Linux Enterprise High Performance Computing 15-ESPOS:opensc-0.18.0-150000.3.23.1
SUSE Linux Enterprise High Performance Computing 15-LTSS:opensc-0.18.0-150000.3.23.1
SUSE Linux Enterprise Server 15-LTSS:opensc-0.18.0-150000.3.23.1
SUSE Linux Enterprise Server for SAP Applications 15:opensc-0.18.0-150000.3.23.1

Ссылки

Описание

OpenSC before 0.20.0 has a double free in coolkey_free_private_data because coolkey_add_object in libopensc/card-coolkey.c lacks a uniqueness check.


Затронутые продукты
SUSE Linux Enterprise High Performance Computing 15-ESPOS:opensc-0.18.0-150000.3.23.1
SUSE Linux Enterprise High Performance Computing 15-LTSS:opensc-0.18.0-150000.3.23.1
SUSE Linux Enterprise Server 15-LTSS:opensc-0.18.0-150000.3.23.1
SUSE Linux Enterprise Server for SAP Applications 15:opensc-0.18.0-150000.3.23.1

Ссылки

Описание

sc_context_create in ctx.c in libopensc in OpenSC 0.19.0 has a memory leak, as demonstrated by a call from eidenv.


Затронутые продукты
SUSE Linux Enterprise High Performance Computing 15-ESPOS:opensc-0.18.0-150000.3.23.1
SUSE Linux Enterprise High Performance Computing 15-LTSS:opensc-0.18.0-150000.3.23.1
SUSE Linux Enterprise Server 15-LTSS:opensc-0.18.0-150000.3.23.1
SUSE Linux Enterprise Server for SAP Applications 15:opensc-0.18.0-150000.3.23.1

Ссылки

Описание

The Oberthur smart card software driver in OpenSC before 0.21.0-rc1 has a heap-based buffer overflow in sc_oberthur_read_file.


Затронутые продукты
SUSE Linux Enterprise High Performance Computing 15-ESPOS:opensc-0.18.0-150000.3.23.1
SUSE Linux Enterprise High Performance Computing 15-LTSS:opensc-0.18.0-150000.3.23.1
SUSE Linux Enterprise Server 15-LTSS:opensc-0.18.0-150000.3.23.1
SUSE Linux Enterprise Server for SAP Applications 15:opensc-0.18.0-150000.3.23.1

Ссылки

Описание

The gemsafe GPK smart card software driver in OpenSC before 0.21.0-rc1 has a stack-based buffer overflow in sc_pkcs15emu_gemsafeGPK_init.


Затронутые продукты
SUSE Linux Enterprise High Performance Computing 15-ESPOS:opensc-0.18.0-150000.3.23.1
SUSE Linux Enterprise High Performance Computing 15-LTSS:opensc-0.18.0-150000.3.23.1
SUSE Linux Enterprise Server 15-LTSS:opensc-0.18.0-150000.3.23.1
SUSE Linux Enterprise Server for SAP Applications 15:opensc-0.18.0-150000.3.23.1

Ссылки

Описание

The TCOS smart card software driver in OpenSC before 0.21.0-rc1 has a stack-based buffer overflow in tcos_decipher.


Затронутые продукты
SUSE Linux Enterprise High Performance Computing 15-ESPOS:opensc-0.18.0-150000.3.23.1
SUSE Linux Enterprise High Performance Computing 15-LTSS:opensc-0.18.0-150000.3.23.1
SUSE Linux Enterprise Server 15-LTSS:opensc-0.18.0-150000.3.23.1
SUSE Linux Enterprise Server for SAP Applications 15:opensc-0.18.0-150000.3.23.1

Ссылки

Описание

A heap use after free issue was found in Opensc before version 0.22.0 in sc_file_valid.


Затронутые продукты
SUSE Linux Enterprise High Performance Computing 15-ESPOS:opensc-0.18.0-150000.3.23.1
SUSE Linux Enterprise High Performance Computing 15-LTSS:opensc-0.18.0-150000.3.23.1
SUSE Linux Enterprise Server 15-LTSS:opensc-0.18.0-150000.3.23.1
SUSE Linux Enterprise Server for SAP Applications 15:opensc-0.18.0-150000.3.23.1

Ссылки

Описание

A use after return issue was found in Opensc before version 0.22.0 in insert_pin function that could potentially crash programs using the library.


Затронутые продукты
SUSE Linux Enterprise High Performance Computing 15-ESPOS:opensc-0.18.0-150000.3.23.1
SUSE Linux Enterprise High Performance Computing 15-LTSS:opensc-0.18.0-150000.3.23.1
SUSE Linux Enterprise Server 15-LTSS:opensc-0.18.0-150000.3.23.1
SUSE Linux Enterprise Server for SAP Applications 15:opensc-0.18.0-150000.3.23.1

Ссылки

Описание

Heap buffer overflow issues were found in Opensc before version 0.22.0 in pkcs15-oberthur.c that could potentially crash programs using the library.


Затронутые продукты
SUSE Linux Enterprise High Performance Computing 15-ESPOS:opensc-0.18.0-150000.3.23.1
SUSE Linux Enterprise High Performance Computing 15-LTSS:opensc-0.18.0-150000.3.23.1
SUSE Linux Enterprise Server 15-LTSS:opensc-0.18.0-150000.3.23.1
SUSE Linux Enterprise Server for SAP Applications 15:opensc-0.18.0-150000.3.23.1

Ссылки

Описание

Stack buffer overflow issues were found in Opensc before version 0.22.0 in various places that could potentially crash programs using the library.


Затронутые продукты
SUSE Linux Enterprise High Performance Computing 15-ESPOS:opensc-0.18.0-150000.3.23.1
SUSE Linux Enterprise High Performance Computing 15-LTSS:opensc-0.18.0-150000.3.23.1
SUSE Linux Enterprise Server 15-LTSS:opensc-0.18.0-150000.3.23.1
SUSE Linux Enterprise Server for SAP Applications 15:opensc-0.18.0-150000.3.23.1

Ссылки
Уязвимость SUSE-SU-2022:1041-1