Gentoo Forums
Gentoo Forums
Gentoo Forums
Quick Search: in
[ GLSA 200908-01 ] OpenSC: Multiple vulnerabilities
View unanswered posts
View posts from last 24 hours

 
Reply to topic    Gentoo Forums Forum Index News & Announcements
View previous topic :: View next topic  
Author Message
GLSA
Advocate
Advocate


Joined: 12 May 2004
Posts: 2663

PostPosted: Sat Aug 22, 2009 1:26 am    Post subject: [ GLSA 200908-01 ] OpenSC: Multiple vulnerabilities Reply with quote

Gentoo Linux Security Advisory

Title: OpenSC: Multiple vulnerabilities (GLSA 200908-01)
Severity: normal
Exploitable: local
Date: August 01, 2009
Bug(s): #260514, #269920
ID: 200908-01

Synopsis


Multiple vulnerabilities were found in OpenSC.


Background


OpenSC provides a set of libraries and utilities to access smart cards.


Affected Packages

Package: dev-libs/opensc
Vulnerable: < 0.11.8
Unaffected: >= 0.11.8
Architectures: All supported architectures


Description


Multiple vulnerabilities were found in OpenSC:
  • b.badrignans discovered that OpenSC incorrectly initialises private
    data objects (CVE-2009-0368).
  • Miquel Comas Marti discovered
    that src/tools/pkcs11-tool.c in pkcs11-tool in OpenSC 0.11.7, when used
    with unspecified third-party PKCS#11 modules, generates RSA keys with
    incorrect public exponents (CVE-2009-1603).


Impact


The first vulnerabilty allows physically proximate attackers to bypass
intended PIN requirements and read private data objects. The second
vulnerability allows attackers to read the cleartext form of messages
that were intended to be encrypted.

NOTE: Smart cards which were initialised using an affected version of
OpenSC need to be modified or re-initialised. See the vendor's advisory
for details.


Workaround


There is no known workaround at this time.


Resolution


All OpenSC users should upgrade to the latest version:
Code:
# emerge --sync
    # emerge --ask --oneshot --verbose ">=dev-libs/opensc-0.11.8"


References

CVE-2009-0368
CVE-2009-1603
OpenSC Security Advisory
Back to top
View user's profile Send private message
Display posts from previous:   
Reply to topic    Gentoo Forums Forum Index News & Announcements All times are GMT
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum