Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Debian 10 Buster DLA-3463-1 Critical: Opensc Buffer Overflow Threat

debian lts
Calendar Grey June 21, 2023
Dist Debian Esm H88
Various vulnerabilities identified in opensc may result in system crashes or unauthorized data disclosure. It is advisable to update your Debian installations.
Multiple vulnerabilities were found in opensc, a set of libraries and utilities to access smart cards, which could lead to application crash or information leak

Summary

CVE-2019-6502

Dhiraj Mishra discovered a minor memory leak in the eidenv(1) CLI
utility on an error-case.

CVE-2021-42779

A heap use after free vulnerability was discovered in
sc_file_valid().

CVE-2021-42780

An use after return vulnerability was discovered in insert_pin(),
which could potentially crash programs using the library.

CVE-2021-42781

Multiple heap buffer overflow vulnerabilities were discovered in
pkcs15-oberthur.c, which could potentially crash programs using the
library.

CVE-2021-42782

Multiple stack buffer overflow vulnerabilities were discovered in
various places, which could potentially crash programs using the
library.

CVE-2023-2977

A buffer overrun vulnerability was discovered in pkcs15
cardos_have_verifyrc_package(), which could lead to crash or
information leak via smart card package with a malicious ASN1
context.

For Debian 10 buster, these problems have been fixed in version
0.19.0-1+deb10u2.

Read the Full Advisory


Severity
critical
Lowest
Low
Medium
High
Critical

Package: opensc
Version: 0.19.0-1+deb10u2
CVE ID: CVE-2019-6502 CVE-2021-42779 CVE-2021-42780 CVE-2021-42781
Debian Bug: 1037021

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here