Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

Mageia 8 MGASA-2021-0512 Moderate: OpenSC Multiple Memory Issues

mageia
Calendar Grey November 18, 2021
Dist Mageia Esm H88
Mageia 2021-0513 addresses critical flaws in OpenSC. Updates tackle heap corruption and input validation weaknesses.
CVE-2021-42780: Fixed use after return in insert_pin() (bsc#1192005)

Summary

CVE-2021-42780: Fixed use after return in insert_pin() (bsc#1192005). CVE-2021-42779: Fixed use after free in sc_file_valid() (bsc#1191992). CVE-2021-42781: Fixed multiple heap buffer overflows in pkcs15-oberthur.c (bsc#1192000). CVE-2021-42782: Stack buffer overflow issues in various places (bsc#1191957).

References

- https://bugs.mageia.org/show_bug.cgi?id=29607

- https://lists.suse.com/pipermail/sle-security-updates/2021-October/009683.html

- https://www.cve.org/CVERecord?id=CVE-2021-42779

- https://www.cve.org/CVERecord?id=CVE-2021-42780

- https://www.cve.org/CVERecord?id=CVE-2021-42781

- https://www.cve.org/CVERecord?id=CVE-2021-42782

Resolution

SRPMS

- 8/core/opensc-0.22.0-1.mga8

Publication date: 18 Nov 2021
URL: https://advisories.mageia.org/MGASA-2021-0512.html
Type: security
CVE: CVE-2021-42779, CVE-2021-42780, CVE-2021-42781, CVE-2021-42782

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here