Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

openSUSE 15.2: 2021:0565-1 Moderate: opensc Security Update

opensuse
Calendar Grey April 16, 2021
Dist Opensuse Esm H88
Updates addressing 8 security flaws found in opensc have been released for openSUSE, improving the overall safety and reliability of the system.
An update that fixes 8 vulnerabilities is now available

Description

This update for opensc fixes the following issues:

- CVE-2019-15945: Fixed an out-of-bounds access of an ASN.1 Bitstring in

decode_bit_string (bsc#1149746).

- CVE-2019-15946: Fixed an out-of-bounds access of an ASN.1 Octet string

in asn1_decode_entry (bsc#1149747)

- CVE-2019-19479: Fixed an incorrect read operation during parsing of a

SETCOS file attribute (bsc#1158256)

- CVE-2019-19480: Fixed an improper free operation in

sc_pkcs15_decode_prkdf_entry (bsc#1158307).

- CVE-2019-20792: Fixed a double free in coolkey_free_private_data

(bsc#1170809).

- CVE-2020-26570: Fixed a buffer overflow in sc_oberthur_read_file

(bsc#1177364).

- CVE-2020-26571: Fixed a stack-based buffer overflow in gemsafe GPK smart

card software driver (bsc#1177380)

- CVE-2020-26572: Fixed a stack-based buffer overflow in tcos_decipher

(bsc#1177378).

This update was imported from the SUSE:SLE-15-SP1:Update update project.

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 15.2:

zypper in -t patch openSUSE-2021-565=1

Package List

- openSUSE Leap 15.2 (i586 x86_64):

opensc-0.19.0-lp152.3.3.1

opensc-debuginfo-0.19.0-lp152.3.3.1

opensc-debugsource-0.19.0-lp152.3.3.1

- openSUSE Leap 15.2 (x86_64):

opensc-32bit-0.19.0-lp152.3.3.1

opensc-32bit-debuginfo-0.19.0-lp152.3.3.1

References

https://www.suse.com/security/cve/CVE-2019-15945.html

https://www.suse.com/security/cve/CVE-2019-15946.html

https://www.suse.com/security/cve/CVE-2019-19479.html

https://www.suse.com/security/cve/CVE-2019-19480.html

https://www.suse.com/security/cve/CVE-2019-20792.html

https://www.suse.com/security/cve/CVE-2020-26570.html

https://www.suse.com/security/cve/CVE-2020-26571.html

https://www.suse.com/security/cve/CVE-2020-26572.html

https://bugzilla.suse.com/1149746

https://bugzilla.suse.com/1149747

https://bugzilla.suse.com/1158256

https://bugzilla.suse.com/1158307

https://bugzilla.suse.com/1170809

https://bugzilla.suse.com/1177364

https://bugzilla.suse.com/1177378

https://bugzilla.suse.com/1177380

Announcement ID: openSUSE-SU-2021:0565-1
Rating: moderate
Affected Products: openSUSE Leap 15.2 .

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here