Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2024:1625-1

Опубликовано: 13 мая 2024
Источник: suse-cvrf

Описание

Security update for opensc

This update for opensc fixes the following issues:

  • CVE-2023-5992: Fixed a side-channel leaks while stripping encryption PKCS#1 padding (bsc#1219386)

Список пакетов

SUSE Linux Enterprise Server 12 SP5
opensc-0.13.0-3.28.1
SUSE Linux Enterprise Server for SAP Applications 12 SP5
opensc-0.13.0-3.28.1

Описание

A vulnerability was found in OpenSC where PKCS#1 encryption padding removal is not implemented as side-channel resistant. This issue may result in the potential leak of private data.


Затронутые продукты
SUSE Linux Enterprise Server 12 SP5:opensc-0.13.0-3.28.1
SUSE Linux Enterprise Server for SAP Applications 12 SP5:opensc-0.13.0-3.28.1

Ссылки
Уязвимость SUSE-SU-2024:1625-1