ALT-BU-2020-3784-1
Branch sisyphus update bulletin.
Closed bugs
pam: can't login, pam_motd failed
Closed vulnerabilities
BDU:2022-00268
Уязвимость набора программных инструментов и библиотек для работы со смарт-картами OpenSC, связанная с выходом операции за границы буфера в памяти, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании
BDU:2022-00271
Уязвимость набора программных инструментов и библиотек для работы со смарт-картами OpenSC, связанная с чтением за допустимыми границами буфера данных, позволяющая нарушителю получить доступ к конфиденциальным данным
BDU:2022-00273
Уязвимость набора программных инструментов и библиотек для работы со смарт-картами OpenSC, связанная с неправильным освобождением памяти перед удалением последний ссылки, позволяющая нарушителю вызвать отказ в обслуживании
BDU:2022-00332
Уязвимость набора программных инструментов и библиотек для работы со смарт-картами OpenSC, связанная с выходом операции за границы буфера в памяти, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании
Modified: 2024-11-21
CVE-2019-15945
OpenSC before 0.20.0-rc1 has an out-of-bounds access of an ASN.1 Bitstring in decode_bit_string in libopensc/asn1.c.
- [oss-security] 20191229 OpenSC 0.20.0 released
- [oss-security] 20191229 OpenSC 0.20.0 released
- https://github.com/OpenSC/OpenSC/commit/412a6142c27a5973c61ba540e33cdc22d5608e68
- https://github.com/OpenSC/OpenSC/commit/412a6142c27a5973c61ba540e33cdc22d5608e68
- https://github.com/OpenSC/OpenSC/compare/f1691fc...12218d4
- https://github.com/OpenSC/OpenSC/compare/f1691fc...12218d4
- [debian-lts-announce] 20190911 [SECURITY] [DLA 1916-1] opensc security update
- [debian-lts-announce] 20190911 [SECURITY] [DLA 1916-1] opensc security update
- [debian-lts-announce] 20211129 [SECURITY] [DLA 2832-1] opensc security update
- [debian-lts-announce] 20211129 [SECURITY] [DLA 2832-1] opensc security update
- FEDORA-2020-3c93790abe
- FEDORA-2020-3c93790abe
Modified: 2024-11-21
CVE-2019-15946
OpenSC before 0.20.0-rc1 has an out-of-bounds access of an ASN.1 Octet string in asn1_decode_entry in libopensc/asn1.c.
- [oss-security] 20191229 OpenSC 0.20.0 released
- [oss-security] 20191229 OpenSC 0.20.0 released
- https://github.com/OpenSC/OpenSC/commit/a3fc7693f3a035a8a7921cffb98432944bb42740
- https://github.com/OpenSC/OpenSC/commit/a3fc7693f3a035a8a7921cffb98432944bb42740
- https://github.com/OpenSC/OpenSC/compare/f1691fc...12218d4
- https://github.com/OpenSC/OpenSC/compare/f1691fc...12218d4
- [debian-lts-announce] 20190911 [SECURITY] [DLA 1916-1] opensc security update
- [debian-lts-announce] 20190911 [SECURITY] [DLA 1916-1] opensc security update
- [debian-lts-announce] 20211129 [SECURITY] [DLA 2832-1] opensc security update
- [debian-lts-announce] 20211129 [SECURITY] [DLA 2832-1] opensc security update
- FEDORA-2020-3c93790abe
- FEDORA-2020-3c93790abe
Modified: 2024-11-21
CVE-2019-19479
An issue was discovered in OpenSC through 0.19.0 and 0.20.x through 0.20.0-rc3. libopensc/card-setcos.c has an incorrect read operation during parsing of a SETCOS file attribute.
- [oss-security] 20191229 OpenSC 0.20.0 released
- [oss-security] 20191229 OpenSC 0.20.0 released
- https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=18693
- https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=18693
- https://github.com/OpenSC/OpenSC/commit/c3f23b836e5a1766c36617fe1da30d22f7b63de2
- https://github.com/OpenSC/OpenSC/commit/c3f23b836e5a1766c36617fe1da30d22f7b63de2
- [debian-lts-announce] 20191226 [SECURITY] [DLA 2046-1] opensc security update
- [debian-lts-announce] 20191226 [SECURITY] [DLA 2046-1] opensc security update
- [debian-lts-announce] 20211129 [SECURITY] [DLA 2832-1] opensc security update
- [debian-lts-announce] 20211129 [SECURITY] [DLA 2832-1] opensc security update
- FEDORA-2020-3c93790abe
- FEDORA-2020-3c93790abe
Modified: 2024-11-21
CVE-2019-19480
An issue was discovered in OpenSC through 0.19.0 and 0.20.x through 0.20.0-rc3. libopensc/pkcs15-prkey.c has an incorrect free operation in sc_pkcs15_decode_prkdf_entry.
- [oss-security] 20191229 OpenSC 0.20.0 released
- [oss-security] 20191229 OpenSC 0.20.0 released
- https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=18478
- https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=18478
- https://github.com/OpenSC/OpenSC/commit/6ce6152284c47ba9b1d4fe8ff9d2e6a3f5ee02c7
- https://github.com/OpenSC/OpenSC/commit/6ce6152284c47ba9b1d4fe8ff9d2e6a3f5ee02c7
- FEDORA-2020-3c93790abe
- FEDORA-2020-3c93790abe
Modified: 2024-11-21
CVE-2019-19481
An issue was discovered in OpenSC through 0.19.0 and 0.20.x through 0.20.0-rc3. libopensc/card-cac1.c mishandles buffer limits for CAC certificates.
- [oss-security] 20191229 OpenSC 0.20.0 released
- [oss-security] 20191229 OpenSC 0.20.0 released
- https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=18618
- https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=18618
- https://github.com/OpenSC/OpenSC/commit/b75c002cfb1fd61cd20ec938ff4937d7b1a94278
- https://github.com/OpenSC/OpenSC/commit/b75c002cfb1fd61cd20ec938ff4937d7b1a94278
- FEDORA-2020-3c93790abe
- FEDORA-2020-3c93790abe
Modified: 2024-11-21
CVE-2019-20792
OpenSC before 0.20.0 has a double free in coolkey_free_private_data because coolkey_add_object in libopensc/card-coolkey.c lacks a uniqueness check.
- https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=19208
- https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=19208
- https://github.com/OpenSC/OpenSC/commit/c246f6f69a749d4f68626b40795a4f69168008f4
- https://github.com/OpenSC/OpenSC/commit/c246f6f69a749d4f68626b40795a4f69168008f4
- https://github.com/OpenSC/OpenSC/compare/0.19.0...0.20.0
- https://github.com/OpenSC/OpenSC/compare/0.19.0...0.20.0
Modified: 2024-11-21
CVE-2019-6502
sc_context_create in ctx.c in libopensc in OpenSC 0.19.0 has a memory leak, as demonstrated by a call from eidenv.
- [oss-security] 20191229 OpenSC 0.20.0 released
- https://github.com/OpenSC/OpenSC/issues/1586
- [debian-lts-announce] 20230621 [SECURITY] [DLA 3463-1] opensc security update
- [oss-security] 20191229 OpenSC 0.20.0 released
- [debian-lts-announce] 20230621 [SECURITY] [DLA 3463-1] opensc security update
- https://github.com/OpenSC/OpenSC/issues/1586