Mageia 2019-0019: opensc security update
Summary
Several buffer overflows when handling responses from a Muscle Card in
muscle_list_files in libopensc/card-muscle.c in OpenSC before 0.19.0-rc1
could be used by attackers able to supply crafted smartcards to cause a
denial of service (application crash) or possibly have unspecified other
impact (CVE-2018-16391).
Several buffer overflows when handling responses from a TCOS Card in
tcos_select_file in libopensc/card-tcos.c in OpenSC before 0.19.0-rc1
could be used by attackers able to supply crafted smartcards to cause a
denial of service (application crash) or possibly have unspecified other
impact (CVE-2018-16392).
Several buffer overflows when handling responses from a Gemsafe V1
Smartcard in gemsafe_get_cert_len in libopensc/pkcs15-gemsafeV1.c in
OpenSC before 0.19.0-rc1 could be used by attackers able to supply
crafted smartcards to cause a denial of service (application crash) or
possibly have unspecified other impact (CVE-2018-16393).
A buffer overflow when handling string conc...
References
- https://bugs.mageia.org/show_bug.cgi?id=23447
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/FELOINZJEHXTJ757WSU4HYL5HWENARJH/
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-16391
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-16392
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-16393
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-16418
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-16419
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-16420
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-16421
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-16422
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-16423
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-16424
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-16425
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-16426
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-16427
Resolution
MGASA-2019-0019 - Updated opensc packages fix security vulnerabilities
SRPMS
- 6/core/opensc-0.19.0-1.mga6