Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Mageia 2025-0096: opensc Security Advisory Updates

mageia
Calendar Grey March 13, 2025
Dist Mageia Esm H88
Critical updates for Mageia address buffer overflow and uninitialized values in opensc packages to protect systems.
Heap buffer overflow in openpgp driver when generating key

Summary

Heap buffer overflow in openpgp driver when generating key. (CVE-2024-8443) Usage of uninitialized values in libopensc and pkcs15init. (CVE-2024-45615) Uninitialized values after incorrect check or usage of apdu response values in libopensc. (CVE-2024-45616) Uninitialized values after incorrect or missing checking return values of functions in libopensc. (CVE-2024-45617) Uninitialized values after incorrect or missing checking return values of functions in pkcs15init. (CVE-2024-45618) Incorrect handling length of buffers or files in libopensc. (CVE-2024-45619) Incorrect handling of the length of buffers or files in pkcs15init. (CVE-2024-45620)

References

- https://bugs.mageia.org/show_bug.cgi?id=34087

- https://ubuntu.com/security/notices/USN-7346-1

- https://www.cve.org/CVERecord?id=CVE-2024-8443

- https://www.cve.org/CVERecord?id=CVE-2024-45615

- https://www.cve.org/CVERecord?id=CVE-2024-45616

- https://www.cve.org/CVERecord?id=CVE-2024-45617

- https://www.cve.org/CVERecord?id=CVE-2024-45618

- https://www.cve.org/CVERecord?id=CVE-2024-45619

- https://www.cve.org/CVERecord?id=CVE-2024-45620

Resolution

SRPMS

- 9/core/opensc-0.25.0-1.1.mga9

Severity
important
Lowest
Low
Medium
High
Critical

Publication date: 13 Mar 2025
URL: https://advisories.mageia.org/MGASA-2025-0096.html
Type: security
CVE: CVE-2024-8443, CVE-2024-45615, CVE-2024-45616, CVE-2024-45617, CVE-2024-45618, CVE-2024-45619, CVE-2024-45620

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here