Debian Security Advisory

DSA-1734-1 opensc -- programming error

Date Reported:
05 Mar 2009
Affected Packages:
Security database references:
In Mitre's CVE dictionary: CVE-2009-0368.
More information:

b.badrignans discovered that OpenSC, a set of smart card utilities, could stores private data on a smart card without proper access restrictions.

Only blank cards initialised with OpenSC are affected by this problem. This update only improves creating new private data objects, but cards already initialised with such private data objects need to be modified to repair the access control conditions on such cards. Instructions for a variety of situations can be found at the OpenSC web site:

The oldstable distribution (etch) is not affected by this problem.

For the stable distribution (lenny), this problem has been fixed in version 0.11.4-5+lenny1.

For the unstable distribution (sid), this problem wil be fixed soon.

We recommend that you upgrade your opensc package and recreate any private data objects stored on your smart cards.

Fixed in:

Debian GNU/Linux 5.0 (lenny)

Intel IA-32:
Intel IA-64:
Big-endian MIPS:
Little-endian MIPS:
IBM S/390:

MD5 checksums of the listed files are available in the original advisory.